SDNShield: Towards More Comprehensive Defense against DDoS Attacks on SDN Control Plane

被引:0
|
作者
Chen, Kuan-yin [1 ]
Junuthula, Anudeep Reddy [1 ]
Siddhrau, Ishant Kumar [1 ]
Xu, Yang [1 ]
Chao, H. Jonathan [1 ]
机构
[1] NYU, Tandon Sch Engn, Dept Elect & Comp Engn, Brooklyn, NY 10003 USA
基金
美国国家科学基金会;
关键词
software-defined network (SDN); distributed denial-of-service (DDoS); scalability; security;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
While the software-defined networking (SDN) paradigm is gaining much popularity, current SDN infrastructure has potential bottlenecks in the control plane, hindering the network's capability of handling on-demand, fine-grained flow level visibility and controllability. Adversaries can exploit these vulnerabilities to launch distributed denial-of-service (DDoS) attacks against the SDN infrastructure. Recently proposed solutions either scale up the SDN control plane or filter out forged traffic, but not both. We propose SDNShield, a combined solution towards more comprehensive defense against DDoS attacks on SDN control plane. SDNShield deploys specialized software boxes to improve the scalability of ingress SDN switches to accommodate control plane workload surges. It further incorporates a two-stage filtering scheme to protect the centralized controller. The first stage statistically distinguishes legitimate flows from forged ones, and the second stage recovers the false positives of the first stage with in-depth TCP handshake verification. Prototype tests and dataset-driven evaluation results show that SDNShield maintains higher resilience than existing solutions under varying attack intensity.
引用
收藏
页码:28 / 36
页数:9
相关论文
共 50 条
  • [21] A protocol for cluster confirmations of SDN controllers against DDoS attacks
    Iranmanesh, Amir
    Naji, Hamid Reza
    COMPUTERS & ELECTRICAL ENGINEERING, 2021, 93
  • [22] Bungee-ML: A Cross-Plane Approach for a Collaborative Defense Against DDoS Attacks
    Libardo Andrey Quintero González
    Lucas Castanheira
    Jonatas A. Marques
    Alberto E. Schaeffer-Filho
    Luciano Paschoal Gaspary
    Journal of Network and Systems Management, 2023, 31
  • [23] Bungee-ML: A Cross-Plane Approach for a Collaborative Defense Against DDoS Attacks
    Gonzalez, Libardo Andrey Quintero
    Castanheira, Lucas
    Marques, Jonatas A.
    Schaeffer-Filho, Alberto E.
    Gaspary, Luciano Paschoal
    JOURNAL OF NETWORK AND SYSTEMS MANAGEMENT, 2023, 31 (04)
  • [24] Detection and Defense Mechanisms Against DDoS Attacks: A Review
    Pimpalkar, Archana S.
    Patil, A. R. Bhagat
    2015 INTERNATIONAL CONFERENCE ON INNOVATIONS IN INFORMATION, EMBEDDED AND COMMUNICATION SYSTEMS (ICIIECS), 2015,
  • [25] Towards Cost-Effective Moving Target Defense Against DDoS and Covert Channel Attacks
    Wang, Huangxin
    Li, Fei
    Chen, Songqing
    MTD'16: PROCEEDINGS OF THE 2016 ACM WORKSHOP ON MOVING TARGET DEFENSE, 2016, : 15 - 25
  • [26] An SDN-based Approach For Defending Against Reflective DDoS Attacks
    Lukaseder, Thomas
    StOlzle, Kevin
    Kleber, Stephan
    Erb, Benjamin
    Kargl, Frank
    PROCEEDINGS OF THE 2018 IEEE 43RD CONFERENCE ON LOCAL COMPUTER NETWORKS (LCN), 2018, : 299 - 302
  • [27] Uncovering collateral damages and advanced defense strategies in cloud environments against DDoS attacks: A comprehensive review
    Verma, Priyanka
    Bharot, Nitesh
    Breslin, John G.
    Sharma, Mukta
    Chaurasia, Nisha
    Vidyarthi, Ankit
    TRANSACTIONS ON EMERGING TELECOMMUNICATIONS TECHNOLOGIES, 2024, 35 (04)
  • [28] A comprehensive review of vulnerabilities and AI-enabled defense against DDoS attacks for securing cloud services
    Kumar, Surendra
    Dwivedi, Mridula
    Kumar, Mohit
    Gill, Sukhpal Singh
    COMPUTER SCIENCE REVIEW, 2024, 53
  • [29] Multi-Defense Mechanism against DDoS in SDN based CDNi
    Nishat-I-Mowla
    Doh, Inshil
    Chae, Kijoon
    2014 Eighth International Conference on Innovative Mobile and Internet Services in Ubiquitous Computing (IMIS), 2014, : 447 - 451
  • [30] MSOM: Efficient Mechanism for Defense against DDoS Attacks in VANET
    Al-Mehdhara, Mohammed
    Ruan, Na
    WIRELESS COMMUNICATIONS & MOBILE COMPUTING, 2021, 2021