Detection and mitigation of DDoS attacks based on multi-dimensional characteristics in SDN

被引:0
|
作者
Kun Wang
Yu Fu
Xueyuan Duan
Taotao Liu
机构
[1] Naval University of Engineering,Department of Information Security
[2] Xinyang Vocational and Technical College,School of Mathematics and Information Engineering
[3] Xinyang Normal University,College of Computer and Information Technology
[4] Henan Key Laboratory of Analysis and Applications of Education Big Data,undefined
关键词
Deep learning; Software defined network; Distributed denial of service; Attack detection;
D O I
10.1038/s41598-024-66907-z
中图分类号
学科分类号
摘要
Due to the large computational overhead, underutilization of features, and high bandwidth consumption in traditional SDN environments for DDoS attack detection and mitigation methods, this paper proposes a two-stage detection and mitigation method for DDoS attacks in SDN based on multi-dimensional characteristics. Firstly, an analysis of the traffic statistics from the SDN switch ports is performed, which aids in conducting a coarse-grained detection of DDoS attacks within the network. Subsequently, a Multi-Dimensional Deep Convolutional Classifier (MDDCC) is constructed using wavelet decomposition and convolutional neural networks to extract multi-dimensional characteristics from the traffic data passing through suspicious switches. Based on these extracted multi-dimensional characteristics, a simple classifier can be employed to accurately detect attack samples. Finally, by integrating graph theory with restrictive strategies, the source of attacks in SDN networks can be effectively traced and isolated. The experimental results indicate that the proposed method, which utilizes a minimal amount of statistical information, can quickly and accurately detect attacks within the SDN network. It demonstrates superior accuracy and generalization capabilities compared to traditional detection methods, especially when tested on both simulated and public datasets. Furthermore, by isolating the affected nodes, the method effectively mitigates the impact of the attacks, ensuring the normal transmission of legitimate traffic during network attacks. This approach not only enhances the detection capabilities but also provides a robust mechanism for containing the spread of cyber threats, thereby safeguarding the integrity and performance of the network.
引用
收藏
相关论文
共 50 条
  • [1] SDN-based detection and mitigation of DDoS attacks on smart homes
    Garba, Usman Haruna
    Toosi, Adel N.
    Pasha, Muhammad Fermi
    Khan, Suleman
    [J]. COMPUTER COMMUNICATIONS, 2024, 221 : 29 - 41
  • [2] DNS Amplification Based DDoS Attacks in SDN Environment: Detection and Mitigation
    Gupta, Vishal
    Kochar, Amrit
    Saharan, Shail
    Kulshrestha, Rakhee
    [J]. 2019 IEEE 4TH INTERNATIONAL CONFERENCE ON COMPUTER AND COMMUNICATION SYSTEMS (ICCCS 2019), 2019, : 473 - 478
  • [3] SDN Based Collaborative Scheme for Mitigation of DDoS Attacks
    Hameed, Sufian
    Khan, Hassan Ahmed
    [J]. FUTURE INTERNET, 2018, 10 (03)
  • [4] One-Dimensional Convolutional Neural Network for Detection and Mitigation of DDoS Attacks in SDN
    Alshra'a, Abdullah
    Jochen, Seitz
    [J]. MACHINE LEARNING FOR NETWORKING, MLN 2021, 2022, 13175 : 11 - 28
  • [5] SDN-Based Intrusion Detection System for Early Detection and Mitigation of DDoS Attacks
    Manso, Pedro
    Moura, Jose
    Serrao, Carlos
    [J]. INFORMATION, 2019, 10 (03)
  • [6] DDoS Attacks Detection and Mitigation in SDN using Machine Learning
    Rahman, Obaid
    Quraishi, Mohammad Ali Gauhar
    Lung, Chung-Horng
    [J]. 2019 IEEE WORLD CONGRESS ON SERVICES (IEEE SERVICES 2019), 2019, : 184 - 189
  • [7] DDoS Attacks and Flash Event Detection Based on Flow Characteristics in SDN
    Sun, Guozi
    Jiang, Wenti
    Gu, Yu
    Ren, Danni
    Li, Huakang
    [J]. 2018 15TH IEEE INTERNATIONAL CONFERENCE ON ADVANCED VIDEO AND SIGNAL BASED SURVEILLANCE (AVSS), 2018, : 556 - 561
  • [8] Neural Network-Based Approach for Detection and Mitigation of DDoS Attacks in SDN Environments
    Hannache, Oussama
    Batouche, Mohamed Chaouki
    [J]. INTERNATIONAL JOURNAL OF INFORMATION SECURITY AND PRIVACY, 2020, 14 (03) : 50 - 71
  • [9] Prevention and Mitigation of DNS based DDoS attacks in SDN Environment
    Saharan, Shail
    Gupta, Vishal
    [J]. 2019 11TH INTERNATIONAL CONFERENCE ON COMMUNICATION SYSTEMS & NETWORKS (COMSNETS), 2019, : 606 - 608
  • [10] Detection and mitigation of DDoS in SDN
    Pande, Bhavika
    Bhagat, Gargi
    Priya, Shanu
    Agrawal, Himanshu
    [J]. 2018 ELEVENTH INTERNATIONAL CONFERENCE ON CONTEMPORARY COMPUTING (IC3), 2018, : 371 - 373