SDNShield: Towards More Comprehensive Defense against DDoS Attacks on SDN Control Plane

被引:0
|
作者
Chen, Kuan-yin [1 ]
Junuthula, Anudeep Reddy [1 ]
Siddhrau, Ishant Kumar [1 ]
Xu, Yang [1 ]
Chao, H. Jonathan [1 ]
机构
[1] NYU, Tandon Sch Engn, Dept Elect & Comp Engn, Brooklyn, NY 10003 USA
基金
美国国家科学基金会;
关键词
software-defined network (SDN); distributed denial-of-service (DDoS); scalability; security;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
While the software-defined networking (SDN) paradigm is gaining much popularity, current SDN infrastructure has potential bottlenecks in the control plane, hindering the network's capability of handling on-demand, fine-grained flow level visibility and controllability. Adversaries can exploit these vulnerabilities to launch distributed denial-of-service (DDoS) attacks against the SDN infrastructure. Recently proposed solutions either scale up the SDN control plane or filter out forged traffic, but not both. We propose SDNShield, a combined solution towards more comprehensive defense against DDoS attacks on SDN control plane. SDNShield deploys specialized software boxes to improve the scalability of ingress SDN switches to accommodate control plane workload surges. It further incorporates a two-stage filtering scheme to protect the centralized controller. The first stage statistically distinguishes legitimate flows from forged ones, and the second stage recovers the false positives of the first stage with in-depth TCP handshake verification. Prototype tests and dataset-driven evaluation results show that SDNShield maintains higher resilience than existing solutions under varying attack intensity.
引用
收藏
页码:28 / 36
页数:9
相关论文
共 50 条
  • [41] Detection and mitigation of DDoS attacks in SDN: A comprehensive review, research challenges and future directions
    Singh, Jagdeep
    Behal, Sunny
    COMPUTER SCIENCE REVIEW, 2020, 37
  • [42] OverWatch: A Cross-Plane DDoS Attack Defense Framework with Collaborative Intelligence in SDN
    Han, Biao
    Yang, Xiangrui
    Sun, Zhigang
    Huang, Jinfeng
    Su, Jinshu
    SECURITY AND COMMUNICATION NETWORKS, 2018,
  • [43] DAD: Domain Adversarial Defense System Against DDoS Attacks in Cloud
    Divyasree, I. R.
    Selvamani, K.
    IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2022, 19 (01): : 554 - 568
  • [44] A collaborative defense mechanism against DDoS attacks for network service continuity
    Park, PyungKoo
    Yoo, Seongmin
    Ryu, Hoyong
    Park, Jaehyung
    Chung, Kyung-Ho
    Ryou, Jaecheol
    ASIA LIFE SCIENCES, 2015, : 93 - 107
  • [45] IoT standard platform architecture that provides defense against DDoS attacks
    Lee, Yun-kyung
    Kim, Young-ho
    Kim, Jeong-nyeo
    2021 IEEE INTERNATIONAL CONFERENCE ON CONSUMER ELECTRONICS-ASIA (ICCE-ASIA), 2021,
  • [46] TDFA: Traceback-based Defense against DDoS Flooding Attacks
    Foroushani, Vahid Aghaei
    Zincir-Heywood, A. Nur
    2014 IEEE 28TH INTERNATIONAL CONFERENCE ON ADVANCED INFORMATION NETWORKING AND APPLICATIONS (AINA), 2014, : 597 - 604
  • [47] A comprehensive survey of DDoS defense solutions in SDN: Taxonomy, research challenges, and future directions
    Kaur, Sukhveer
    Kumar, Krishan
    Aggarwal, Naveen
    Singh, Gurdeep
    COMPUTERS & SECURITY, 2021, 110 (110)
  • [48] Filtering-Based Defense Mechanisms Against DDoS Attacks: A Survey
    Kalkan, Kubra
    Gur, Gurkan
    Alagoz, Fatih
    IEEE SYSTEMS JOURNAL, 2017, 11 (04): : 2761 - 2773
  • [49] SmartDefense: A distributed deep defense against DDoS attacks with edge computing
    Myneni, Sowmya
    Chowdhary, Ankur
    Huang, Dijiang
    Alshamrani, Adel
    COMPUTER NETWORKS, 2022, 209
  • [50] FlowGuard: An Intelligent Edge Defense Mechanism Against IoT DDoS Attacks
    Jia, Yizhen
    Zhong, Fangtian
    Alrawais, Arwa
    Gong, Bei
    Cheng, Xiuzhen
    IEEE INTERNET OF THINGS JOURNAL, 2020, 7 (10): : 9552 - 9562