A low-rate DDoS detection and mitigation for SDN using Renyi Entropy with Packet Drop

被引:22
|
作者
Ahalawat, Anchal [1 ]
Babu, Korra Sathya [2 ]
Turuk, Ashok Kumar [1 ]
Patel, Sanjeev [1 ]
机构
[1] Natl Inst Technol Rourkela, Dept Comp Sci & Engn, Rourkela 769008, Odisha, India
[2] Indian Inst Informat Technol Kurnool, Dept Comp Sci & Engn, Kurnool 518007, Andhra Pradesh, India
关键词
SDN; OpenFlow; Low-rate DDoS; Renyi entropy; Information distance; ALGORITHM; PROTECTION; ATTACKS; DEFENSE;
D O I
10.1016/j.jisa.2022.103212
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Software-Defined Networking (SDN) is an approach to network architecture that enables software applications used for intelligent, centralized network management or scheduling. It is gaining popularity due to its flexibility, agility, and scalability feature. SDN provides high network programmability and speeds up the network variation by forwarding the control layer from the data layer. The logically centralized controller is always an attractive target for the Distributed Denial of Service (DDoS) attacks. According to various specifications, the low-rate DDoS attack is often not easy to detect against SDN because attackers behave like legitimate traffic. Hence, it is essential to have a fast and accurate detection model to detect the data layer attack traffic timely so that it could not affect on available resources such as bandwidth, memory, central processing unit (CPU). In this paper, we propose a DDoS detection technique based on Renyi Entropy with Packet Drop (REPD) where packets drop method is used for the purpose of mitigation. The information distance metric has been used to evaluate the fluctuation of network traffic with various probability distributions. Also, an extensive simulation has been carried out on the synthetic data to improve the performance in terms of detection time and accuracy. It was observed that the attained results outperformed the Shannon Entropy (SE), Generalized Entropy, and other statistical distance metrics.
引用
收藏
页数:15
相关论文
共 50 条
  • [1] A low-rate DDoS detection and mitigation for SDN using Renyi Entropy with Packet Drop (vol 68, 103212, 2022)
    Ahalawat, Anchal
    Babu, Korra Sathya
    Turuk, Ashok Kumar
    Patel, Sanjeev
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2022, 70
  • [2] Low-Rate DDoS Attack Detection Using Expectation of Packet Size
    Zhou, Lu
    Liao, Mingchao
    Yuan, Cao
    Zhang, Haoyu
    SECURITY AND COMMUNICATION NETWORKS, 2017,
  • [3] DDoS Detection Based on PCA and Renyi Entropy to Secure SDN
    Kanodia, Krishna
    Kumar, Harsh
    Patel, Sanjeev
    10TH INTERNATIONAL CONFERENCE ON ELECTRONICS, COMPUTING AND COMMUNICATION TECHNOLOGIES, CONECCT 2024, 2024,
  • [4] Low-rate DDoS attack Detection using Deep Learning for SDN-enabled IoT Networks
    Alashhab A.A.
    Zahid M.S.M.
    Muneer A.
    Abdukkahi M.
    International Journal of Advanced Computer Science and Applications, 2022, 13 (11): : 371 - 377
  • [5] Low-rate DDoS attack Detection using Deep Learning for SDN-enabled IoT Networks
    Alashhab, Abdussalam Ahmed
    Zahid, Mohd Soperi Mohd
    Muneer, Amgad
    Abdullahi, Mujaheed
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2022, 13 (11) : 371 - 377
  • [6] Detection and mitigation of DDoS in SDN
    Pande, Bhavika
    Bhagat, Gargi
    Priya, Shanu
    Agrawal, Himanshu
    2018 ELEVENTH INTERNATIONAL CONFERENCE ON CONTEMPORARY COMPUTING (IC3), 2018, : 371 - 373
  • [7] Machine learning based low-rate DDoS attack detection for SDN enabled IoT networks
    Cheng, Haosu
    Liu, Jianwei
    Xu, Tongge
    Ren, Bohan
    Mao, Jian
    Zhang, Wei
    INTERNATIONAL JOURNAL OF SENSOR NETWORKS, 2020, 34 (01) : 56 - 69
  • [8] Research on low-rate DDoS attack of SDN network in cloud environment
    Chen X.
    Hua Q.
    Wang Y.
    Ge L.
    Zhu Y.
    Tongxin Xuebao/Journal on Communications, 2019, 40 (06): : 210 - 222
  • [9] Enhancing Network Security in SDN: Detecting Low-Rate DDoS Attacks Using Decision Trees
    Alomin, Hasen
    Gargouri, Amir
    Ghorbel, Mohamed Ali
    2024 IEEE INTERNATIONAL CONFERENCE ON ADVANCED SYSTEMS AND EMERGENT TECHNOLOGIES, ICASET 2024, 2024,
  • [10] Power spectrum entropy based detection and mitigation of low-rate DoS attacks
    Chen, Zhaomin
    Yeo, Chai Kiat
    Lee, Bu Sung
    Lau, Chiew Tong
    COMPUTER NETWORKS, 2018, 136 : 80 - 94