Research on low-rate DDoS attack of SDN network in cloud environment

被引:0
|
作者
Chen, Xingshu [1 ,2 ]
Hua, Qiang [1 ,2 ]
Wang, Yitong [3 ]
Ge, Long [3 ]
Zhu, Yi [2 ]
机构
[1] College of Cybersecurity, Sichuan University, Chengdu,610065, China
[2] Research Institute of Cybersecurity, Sichuan University, Chengdu,610065, China
[3] College of Computer Science, Sichuan University, Chengdu,610065, China
来源
基金
中国国家自然科学基金;
关键词
Software defined networking - Denial-of-service attack - Network security;
D O I
10.11959/j.issn.1000-436x.2019120
中图分类号
学科分类号
摘要
Aiming at the problems of low-rate DDoS attack detection accuracy in cloud SDN network and the lack of unified framework for data plane and control plane low-rate DDoS attack detection and defense, a unified framework for low-rate DDoS attack detection was proposed. First of all, the validity of the data plane DDoS attacks in low rate was analyzed, on the basis of combining with low-rate of DDoS attacks in the aspect of communications, frequency characteristics, extract the mean value, maximum value, deviation degree and average deviation, survival time of ten dimensions characteristics of five aspects, to achieve the low-rate of DDoS attack detection based on bayesian networks, issued by the controller after the relevant strategies to block the attack flow. Finally, in OpenStack cloud environment, the detection rate of low-rate DDoS attack reaches 99.3% and the CPU occupation rate is 9.04%. It can effectively detect and defend low-rate DDoS attacks. © 2019, Editorial Board of Journal on Communications. All right reserved.
引用
收藏
页码:210 / 222
相关论文
共 50 条
  • [31] Enhanced detection of low-rate DDoS attack patterns using machine learning models
    Bocu, Razvan
    Iavich, Maksim
    [J]. JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2024, 227
  • [32] On a Mathematical Model for Low-Rate Shrew DDoS
    Luo, Jingtang
    Yang, Xiaolong
    Wang, Jin
    Xu, Jie
    Sun, Jian
    Long, Keping
    [J]. IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2014, 9 (07) : 1069 - 1083
  • [33] Disrupting SDN via the Data Plane: A Low-Rate Flow Table Overflow Attack
    Cao, Jiahao
    Xu, Mingwei
    Li, Qi
    Sun, Kun
    Yang, Yuan
    Zheng, Jing
    [J]. SECURITY AND PRIVACY IN COMMUNICATION NETWORKS, SECURECOMM 2017, 2018, 238 : 356 - 376
  • [34] A potential low-rate DoS attack against network firewalls
    Salah, K.
    Sattar, K.
    Sqalli, M.
    Al-Shaer, Ehab
    [J]. SECURITY AND COMMUNICATION NETWORKS, 2011, 4 (02) : 136 - 146
  • [35] Modeling of Low-Rate DDoS-Attacks
    Tarasov, Yaroslav
    Pakulova, Ekaterina
    Basov, Oleg
    [J]. PROCEEDINGS OF THE 12TH INTERNATIONAL CONFERENCE ON SECURITY OF INFORMATION AND NETWORKS (SIN'19), 2019,
  • [36] A New Framework for DDoS Attack Detection and Defense in SDN Environment
    Tan, Liang
    Pan, Yue
    Wu, Jing
    Zhou, Jianguo
    Jiang, Hao
    Deng, Yuchuan
    [J]. IEEE ACCESS, 2020, 8 : 161908 - 161919
  • [37] A Novel Measure for Low-rate and High-rate DDoS Attack Detection using Multivariate Data Analysis
    Hoque, Nazrul
    Bhattacharyya, Dhruba K.
    Kalita, Jugal K.
    [J]. 2016 8TH INTERNATIONAL CONFERENCE ON COMMUNICATION SYSTEMS AND NETWORKS (COMSNETS), 2016,
  • [38] SDN Control Plane Security in Cloud Computing Against DDoS Attack
    Khimabhai, Yadav Ashok
    Rohokale, Vandana
    [J]. INTERNATIONAL CONFERENCE ON ADVANCES IN INFORMATION COMMUNICATION TECHNOLOGY & COMPUTING, 2016, 2016,
  • [39] Performance and Features: Mitigating the Low-Rate TCP-Targeted DoS Attack via SDN
    Tang, Dan
    Yan, Yudong
    Zhang, Siqi
    Chen, Jingwen
    Qin, Zheng
    [J]. IEEE JOURNAL ON SELECTED AREAS IN COMMUNICATIONS, 2022, 40 (01) : 428 - 444
  • [40] Detection of Low-Rate Cloud DDoS Attacks in Frequency Domain Using Fast Hartley Transform
    Neha Agrawal
    Shashikala Tapaswi
    [J]. Wireless Personal Communications, 2020, 112 : 1735 - 1762