SDNShield: Towards More Comprehensive Defense against DDoS Attacks on SDN Control Plane

被引:0
|
作者
Chen, Kuan-yin [1 ]
Junuthula, Anudeep Reddy [1 ]
Siddhrau, Ishant Kumar [1 ]
Xu, Yang [1 ]
Chao, H. Jonathan [1 ]
机构
[1] NYU, Tandon Sch Engn, Dept Elect & Comp Engn, Brooklyn, NY 10003 USA
基金
美国国家科学基金会;
关键词
software-defined network (SDN); distributed denial-of-service (DDoS); scalability; security;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
While the software-defined networking (SDN) paradigm is gaining much popularity, current SDN infrastructure has potential bottlenecks in the control plane, hindering the network's capability of handling on-demand, fine-grained flow level visibility and controllability. Adversaries can exploit these vulnerabilities to launch distributed denial-of-service (DDoS) attacks against the SDN infrastructure. Recently proposed solutions either scale up the SDN control plane or filter out forged traffic, but not both. We propose SDNShield, a combined solution towards more comprehensive defense against DDoS attacks on SDN control plane. SDNShield deploys specialized software boxes to improve the scalability of ingress SDN switches to accommodate control plane workload surges. It further incorporates a two-stage filtering scheme to protect the centralized controller. The first stage statistically distinguishes legitimate flows from forged ones, and the second stage recovers the false positives of the first stage with in-depth TCP handshake verification. Prototype tests and dataset-driven evaluation results show that SDNShield maintains higher resilience than existing solutions under varying attack intensity.
引用
收藏
页码:28 / 36
页数:9
相关论文
共 50 条
  • [1] SDNShield: NFV-Based Defense Framework Against DDoS Attacks on SDN Control Plane
    Chen, Kuan-Yin
    Liu, Sen
    Xu, Yang
    Siddhrau, Ishant Kumar
    Zhou, Siyu
    Guo, Zehua
    Chao, H. Jonathan
    IEEE-ACM TRANSACTIONS ON NETWORKING, 2022, 30 (01) : 1 - 17
  • [2] Defense Mechanisms Against DDoS Attacks in SDN Environment
    Kalkan, Kubra
    Gur, Gurkan
    Alagoz, Fatih
    IEEE COMMUNICATIONS MAGAZINE, 2017, 55 (09) : 175 - 179
  • [3] SDNScore: A Statistical Defense Mechanism Against DDoS Attacks in SDN Environment
    Kalkan, Kubra
    Gur, Gurkan
    Alagoz, Fatih
    2017 IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATIONS (ISCC), 2017, : 669 - 675
  • [4] On an Integrated Security Framework for Defense Against Various DDoS Attacks in SDN
    Wu, Hao
    Hou, Aiqin
    Nie, Weike
    Wu, Chase
    2023 INTERNATIONAL CONFERENCE ON COMPUTING, NETWORKING AND COMMUNICATIONS, ICNC, 2023, : 311 - 317
  • [5] In-design Resilient SDN Control Plane and Elastic Forwarding Against Aggressive DDoS Attacks
    Gillani, Fida
    Al-Shaer, Ehab
    Duan, Qi
    PROCEEDINGS OF THE 5TH ACM WORKSHOP ON MOVING TARGET DEFENSE (MTD'18), 2018, : 80 - 89
  • [6] A Comprehensive Survey of Distributed Defense Techniques against DDoS Attacks
    Sachdeva, Monika
    Singh, Gurvinder
    Kumar, Krishan
    Singh, Kuldip
    INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2009, 9 (12): : 7 - 15
  • [7] Implementation of an SDN-based Security Defense Mechanism Against DDoS Attacks
    Lin, Hsiao-Chung
    Wang, Ping
    JOINT 2016 INTERNATIONAL CONFERENCE ON ECONOMICS AND MANAGEMENT ENGINEERING (ICEME 2016) AND INTERNATIONAL CONFERENCE ON ECONOMICS AND BUSINESS MANAGEMENT (EBM 2016), 2016, : 377 - 383
  • [8] Collaborative Defense Method Against DDoS Attacks on SDN-Architected Cloud Servers
    Zhang, Yiying
    Xu, Yao
    Han, Longzhe
    Liang, Kun
    Li, Wenjing
    ADVANCED INTELLIGENT COMPUTING TECHNOLOGY AND APPLICATIONS, PT IV, ICIC 2024, 2024, 14865 : 362 - 370
  • [9] Source-Based Defense Against DDoS Attacks in SDN Based on sFlow and SOM
    Wang, Meng
    Lu, Yiqin
    Qin, Jiancheng
    IEEE ACCESS, 2022, 10 : 2097 - 2116
  • [10] A Hybrid Lightweight Defense System Against Address Spoofing Based DDoS Attacks in SDN
    Sinha, Mitali
    Bera, Padmalochan
    Satpathy, Manoranjan
    Sahoo, Kshira Sagar
    SECURITY AND PRIVACY, 2025, 8 (02):