Reduction of traffic between switches and IDS for prevention of DoS attack in SDN

被引:0
|
作者
Quingueni, Andre Mbundo [1 ]
Kitsuwan, Nattapong [1 ]
机构
[1] Univ Electrocommun, Dept Comp & Network Engn, Tokyo, Japan
来源
ISCIT 2019: PROCEEDINGS OF 2019 19TH INTERNATIONAL SYMPOSIUM ON COMMUNICATIONS AND INFORMATION TECHNOLOGIES (ISCIT) | 2019年
关键词
Denial of Service (DoS); Intrusion Detection System (IDS); Software Defined Network (SDN);
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Denial of service (DoS) is a process of injecting malicious packets into the network. Intrusion detection system (IDS) is a system used to investigate malicious packets in the network. Software-defined network (SDN) physically separates control plane and data plane. The control plane is moved to a centralized controller, and it makes a decision in the network from a global view. The combination between IDS and SDN allows the prevention of malicious packets to be more efficient due to the advantage of the global view in SDN. IDS needs to communicate with switches to have an access to all end-to-end traffic in the network. The high traffic in the link between switches and IDS results in congestion. The congestion between switches and IDS delays the detection and prevention of malicious traffic. To address this problem, we propose a historical database (Hdb), a scheme to reduce the traffic between switches and IDS, based on the historical information of a sender. The simulation shows that in the average, 54.1% of traffic mirrored to IDS is reduced compared to the conventional schemes.
引用
收藏
页码:277 / 281
页数:5
相关论文
共 50 条
  • [1] DoS Attack Prevention on IPS SDN Networks
    Fares, Awatef Ali Yousef R.
    de Caldas Filho, Francisco L.
    Giozza, William F.
    Canedo, Edna Dias
    Lopes de Mendonca, Fabio Lucio
    Amvame Nze, Georges Daniel
    2019 WORKSHOP ON COMMUNICATION NETWORKS AND POWER SYSTEMS (WCNPS), 2019,
  • [2] DOS Attack Mitigation Strategies on SDN Controller
    Tian, Yun
    Tran, Vincent
    Kuerban, Mutalifu
    2019 IEEE 9TH ANNUAL COMPUTING AND COMMUNICATION WORKSHOP AND CONFERENCE (CCWC), 2019, : 701 - 707
  • [3] Intelligent IDS Chaining for Network Attack Mitigation in SDN
    Zolotukhin, Mikhail
    Kotilainen, Pyry
    Hamalainen, Timo
    2021 17TH INTERNATIONAL CONFERENCE ON MOBILITY, SENSING AND NETWORKING (MSN 2021), 2021, : 786 - 791
  • [4] Accurate Traffic Splitting on SDN Switches
    Rottenstreich, Ori
    Kanizo, Yossi
    Kaplan, Haim
    Rexford, Jennifer
    IEEE JOURNAL ON SELECTED AREAS IN COMMUNICATIONS, 2018, 36 (10) : 2190 - 2201
  • [5] FlowSec: DOS attack Mitigation Strategy on SDN Controller
    Kuerban, Mutalifu
    Tian, Yun
    Yang, Qing
    Jia, Yafei
    Huebert, Brandon
    Poss, David
    2016 IEEE INTERNATIONAL CONFERENCE ON NETWORKING ARCHITECTURE AND STORAGE (NAS), 2016,
  • [6] Entropy-based DoS Attack identification in SDN
    Carvalho, Ranyelson N.
    Bordim, Jacir L.
    Alchieri, Eduardo A. P.
    2019 IEEE INTERNATIONAL PARALLEL AND DISTRIBUTED PROCESSING SYMPOSIUM WORKSHOPS (IPDPSW), 2019, : 627 - 634
  • [7] DoS and DDoS Attack Detection Using Deep Learning and IDS
    Shurman, Mohammad
    Khrais, Rami
    Yateem, Abdulrahman
    INTERNATIONAL ARAB JOURNAL OF INFORMATION TECHNOLOGY, 2020, 17 (4A) : 655 - 661
  • [8] DoS Attack Detection using Packet Statistics in SDN
    Goksel, Nail
    Demirci, Mehmet
    2019 INTERNATIONAL SYMPOSIUM ON NETWORKS, COMPUTERS AND COMMUNICATIONS (ISNCC 2019), 2019,
  • [9] A Machine Learning Approach for Detecting DoS Attacks in SDN Switches
    Abhiroop, T.
    Babu, Sarath
    Manoj, B. S.
    2018 TWENTY FOURTH NATIONAL CONFERENCE ON COMMUNICATIONS (NCC), 2018,
  • [10] DoS Attacks Prevention Using IDS and Data Mining
    Keshri, Anand
    Singh, Sukhpal
    Agarwal, Mayank
    Nandi, Sunit Kumar
    2016 INTERNATIONAL CONFERENCE ON ACCESSIBILITY TO DIGITAL WORLD (ICADW), 2016, : 86 - 91