Toward secure software-defined networks against distributed denial of service attack

被引:0
作者
Kshira Sagar Sahoo
Sanjaya Kumar Panda
Sampa Sahoo
Bibhudatta Sahoo
Ratnakar Dash
机构
[1] National Institute of Technology Rourkela,Department of Computer Science and Engineering
[2] Veer Surendra Sai University of Technology,Department of Information Technology
来源
The Journal of Supercomputing | 2019年 / 75卷
关键词
Software-defined networking; Distributed denial of service attack; Security threat; Security attack; Infrastructure layer; Control layer; Application layer;
D O I
暂无
中图分类号
学科分类号
摘要
The newly emerged software-defined networking (SDN) paradigm provides a flexible network management by decoupling the network control logic from the data plane, which could effectively resolve many security issues of legacy networks. One of such security issues is distributed denial of service (DDoS) attack, which is a rapidly growing network threat. This is usually performed on a target system to make an online service unavailable to the users. SDN can easily detect the DDoS attack due to the centralized control provisioning and network visibility. At the same time, the changes of fundamental architecture and the developments of various design entities pose a severe DDoS threat to the SDN platform. This paper presents a concise up-to-date review of security concerns of SDN, possible DDoS attack in individual layers of SDN and ongoing research efforts on SDN-enabled DDoS detection solutions. Based on the findings, an information distance-based flow discriminator framework has been discussed, which can discriminate the DDoS traffic during flash events, a similar looking legitimate traffic, in SDN environment. The information distance metric is used to describe the variations of traffic behavior of such events. The simulation results show that the information distance metric can effectively identify the DDoS traffic in comparison with other metrics with a higher detection rate. The proposed solution can detect the traffic at the edge switch so that the attack alert can be raised at the earliest.
引用
收藏
页码:4829 / 4874
页数:45
相关论文
共 162 条
  • [1] Mirkovic J(2004)A taxonomy of DDoS attack and DDoS defense mechanisms ACM SIGCOMM Comput Commun Rev 34 39-53
  • [2] Reiher P(2015)Securing software defined networks: taxonomy, requirements and open issues IEEE Commun Mag 53 36-44
  • [3] Akhunzada A(2013)A survey of defense mechanisms against distributed denial of service (DDoS) flooding attacks IEEE Commun Surv Tutor 15 2046-2069
  • [4] Ahmed E(2015)Energy-oriented denial of service attacks: an emerging menace for large cloud infrastructures J Supercomput 71 1620-1641
  • [5] Gani A(2013)A survey on security issues and solutions at different layers of cloud computing J Supercomput 63 561-592
  • [6] Zargar ST(2015)A survey of securing networks using software defined networking IEEE Trans Reliab 64 1086-1097
  • [7] Joshi J(2016)Software-defined networking (SDN) and distributed denial of service (DDoS) attacks in cloud computing environments: a survey, some research issues and challenges IEEE Commun Sur Tutor 18 602-622
  • [8] Tipeer D(2007)Survey of network-based defense mechanisms countering the DoS and DDoS problems ACM Comput Surv 39 1-42
  • [9] Palmieri F(2014)A survey and a layered taxonomy of software-defined networking IEEE Commun Surv Tutor 16 1955-1980
  • [10] Ricciardi S(2017)A survey on software-defined wireless sensor networks: challenges and design requirements IEEE Access 5 1872-1899