Detection and mitigation of UDP flooding attack in a multicontroller software defined network using secure flow management model

被引:9
作者
Gurusamy, UmaMaheswari [1 ]
Hariharan, K. [1 ]
Manikandan, M. S. K. [1 ]
机构
[1] Thiagarajar Coll Engn, Dept Elect & Commun, Madurai 625015, Tamil Nadu, India
关键词
interdomain attack; intradomain attack; multicontroller software-defined network (SDN); pushback requests; secure flow management; UDP flooding attack; DEFENSE-MECHANISMS; SDN; ARCHITECTURE;
D O I
10.1002/cpe.5326
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Software-Defined Networking (SDN) simplifies the network management and provides a way to virtualize, configure, and manage the network infrastructure centrally. The central management has been exhibited by reinforcing an SDN controller, which separates the network data plane from the control functions and is responsible for managing the flows. Distributed Denial-of-Service (DDoS) attacks are the most threatening issue among many security attacks, and it makes the services unavailable in a network. The flow management done by the controller is disrupted when one or more malicious host flood User Datagram Protocol (UDP) packets in the network, focusing on exhausting the bandwidth of the controller. It results in degrading the performance of the controller, leading to control plane saturation. A Secure Flow Management model (SFM), which dynamically identifies and mitigates the UDP flooding attack in a multicontroller SDN has been proposed. The proposed model is a practically applicable defense mechanism against volumetric attack, and it tries to secure the control plane bandwidth. The SFM has been experimented as an extension of the RYU controller and has exploited the attack under different traffic scenarios. Further, an analysis has been made on response time and the CPU utilization taken by the controller to recover from the DoS attack.
引用
收藏
页数:11
相关论文
共 14 条
[1]   LineSwitch: Tackling Control Plane Saturation Attacks in Software-Defined Networking [J].
Ambrosin, Moreno ;
Conti, Mauro ;
De Gaspari, Fabio ;
Poovendran, Radha .
IEEE-ACM TRANSACTIONS ON NETWORKING, 2017, 25 (02) :1206-1219
[2]   A Game Theoretical Based System Using Holt-Winters and Genetic Algorithm With Fuzzy Logic for DoS/DDoS Mitigation on SDN Networks [J].
De Assis, Marcos V. O. ;
Hamamoto, Anderson H. ;
Abrao, Taufik ;
Proenca, Mario Lemes, Jr. .
IEEE ACCESS, 2017, 5 :9485-9496
[3]   A Survey on Large-Scale Software Defined Networking (SDN) Testbeds: Approaches and Challenges [J].
Huang, Tao ;
Yu, F. Richard ;
Zhang, Chen ;
Liu, Jiang ;
Zhang, Jiao ;
Liu, Yunjie .
IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2017, 19 (02) :891-917
[4]   Defense Mechanisms Against DDoS Attacks in SDN Environment [J].
Kalkan, Kubra ;
Gur, Gurkan ;
Alagoz, Fatih .
IEEE COMMUNICATIONS MAGAZINE, 2017, 55 (09) :175-179
[5]   Securing SDN Infrastructure of IoT-Fog Networks From MitM Attacks [J].
Li, Cheng ;
Qin, Zhengrui ;
Novak, Ed ;
Li, Qun .
IEEE INTERNET OF THINGS JOURNAL, 2017, 4 (05) :1156-1164
[6]   SLICOTS: An SDN-Based Lightweight Countermeasure for TCP SYN Flooding Attacks [J].
Mohammadi, Reza ;
Javidan, Reza ;
Conti, Mauro .
IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2017, 14 (02) :487-497
[7]  
ONF, 2013, OPENFL SWITCH SPEC V
[8]   Software Defined Networking Architecture, Security and Energy Efficiency: A Survey [J].
Rawat, Danda B. ;
Reddy, Swetha R. .
IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2017, 19 (01) :325-346
[9]  
RYU Development Team, 2018, RYU DOC REL 4 21
[10]   An Efficient DDoS TCP Flood Attack Detection and Prevention System in a Cloud Environment [J].
Sahi, Aqeel ;
Lai, David ;
Li, Yan ;
Diykh, Mohammed .
IEEE ACCESS, 2017, 5 :6036-6048