A low-rate DDoS detection and mitigation for SDN using Renyi Entropy with Packet Drop

被引:23
|
作者
Ahalawat, Anchal [1 ]
Babu, Korra Sathya [2 ]
Turuk, Ashok Kumar [1 ]
Patel, Sanjeev [1 ]
机构
[1] Natl Inst Technol Rourkela, Dept Comp Sci & Engn, Rourkela 769008, Odisha, India
[2] Indian Inst Informat Technol Kurnool, Dept Comp Sci & Engn, Kurnool 518007, Andhra Pradesh, India
关键词
SDN; OpenFlow; Low-rate DDoS; Renyi entropy; Information distance; ALGORITHM; PROTECTION; ATTACKS; DEFENSE;
D O I
10.1016/j.jisa.2022.103212
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Software-Defined Networking (SDN) is an approach to network architecture that enables software applications used for intelligent, centralized network management or scheduling. It is gaining popularity due to its flexibility, agility, and scalability feature. SDN provides high network programmability and speeds up the network variation by forwarding the control layer from the data layer. The logically centralized controller is always an attractive target for the Distributed Denial of Service (DDoS) attacks. According to various specifications, the low-rate DDoS attack is often not easy to detect against SDN because attackers behave like legitimate traffic. Hence, it is essential to have a fast and accurate detection model to detect the data layer attack traffic timely so that it could not affect on available resources such as bandwidth, memory, central processing unit (CPU). In this paper, we propose a DDoS detection technique based on Renyi Entropy with Packet Drop (REPD) where packets drop method is used for the purpose of mitigation. The information distance metric has been used to evaluate the fluctuation of network traffic with various probability distributions. Also, an extensive simulation has been carried out on the synthetic data to improve the performance in terms of detection time and accuracy. It was observed that the attained results outperformed the Shannon Entropy (SE), Generalized Entropy, and other statistical distance metrics.
引用
收藏
页数:15
相关论文
共 50 条
  • [21] Generalized Network Temperature for DDoS Detection through Renyi Entropy
    Wang, Xiang
    Zhang, Xing
    Wang, Changda
    2022 IEEE 22ND INTERNATIONAL CONFERENCE ON SOFTWARE QUALITY, RELIABILITY, AND SECURITY COMPANION, QRS-C, 2022, : 24 - 33
  • [22] IoT-Based DDoS Attack Detection and Mitigation Using the Edge of SDN
    Yang, Yinqi
    Wang, Jian
    Zhai, Baoqin
    Liu, Jiqiang
    CYBERSPACE SAFETY AND SECURITY, PT II, 2019, 11983 : 3 - 17
  • [23] DDoS attack detection and mitigation using deep neural network in SDN environment
    Hnamte, Vanlalruata
    Najar, Ashfaq Ahmad
    Hong, Nhung-Nguyen
    Hussain, Jamal
    Sugali, Manohar Naik
    COMPUTERS & SECURITY, 2024, 138
  • [24] Early detection of DDoS based on φ-entropy in SDN networks
    Li, Runyu
    Wu, Bin
    PROCEEDINGS OF 2020 IEEE 4TH INFORMATION TECHNOLOGY, NETWORKING, ELECTRONIC AND AUTOMATION CONTROL CONFERENCE (ITNEC 2020), 2020, : 731 - 735
  • [25] SDN-Based Intrusion Detection System for Early Detection and Mitigation of DDoS Attacks
    Manso, Pedro
    Moura, Jose
    Serrao, Carlos
    INFORMATION, 2019, 10 (03)
  • [26] Low-Rate DoS Attack Detection Using PSD based Entropy and Machine Learning
    Zhang, Naiji
    Jaafar, Fehmi
    Malik, Yasir
    2019 6TH IEEE INTERNATIONAL CONFERENCE ON CYBER SECURITY AND CLOUD COMPUTING (IEEE CSCLOUD 2019) / 2019 5TH IEEE INTERNATIONAL CONFERENCE ON EDGE COMPUTING AND SCALABLE CLOUD (IEEE EDGECOM 2019), 2019, : 59 - 62
  • [27] A DDoS Attack Detection Method Using Conditional Entropy Based on SDN Traffic
    Tian, Qiwen
    Miyata, Sumiko
    IOT, 2023, 4 (02): : 95 - 111
  • [28] Detection and Mitigation of Low-Rate Denial-of-Service Attacks: A Survey
    Rios, Vinicius De Miranda
    Inacio, Pedro R. M.
    Magoni, Damien
    Freire, Mario M.
    IEEE ACCESS, 2022, 10 : 76648 - 76668
  • [29] Packet_In message based DDoS attack detection in SDN network using OpenFlow
    You, Xiang
    Feng, Yaokai
    Sakurai, Kouichi
    2017 FIFTH INTERNATIONAL SYMPOSIUM ON COMPUTING AND NETWORKING (CANDAR), 2017, : 522 - 528
  • [30] Time-based DDoS Detection and Mitigation for SDN Controller
    Dharma, I. Gde N.
    Muthohar, M. Fiqri
    Prayuda, Alvin J. D.
    Priagung, K.
    Choi, Deokjai
    2015 17TH ASIA-PACIFIC NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM APNOMS, 2015, : 550 - 553