Detection and mitigation of DDoS attacks based on multi-dimensional characteristics in SDN

被引:0
|
作者
Kun Wang
Yu Fu
Xueyuan Duan
Taotao Liu
机构
[1] Naval University of Engineering,Department of Information Security
[2] Xinyang Vocational and Technical College,School of Mathematics and Information Engineering
[3] Xinyang Normal University,College of Computer and Information Technology
[4] Henan Key Laboratory of Analysis and Applications of Education Big Data,undefined
关键词
Deep learning; Software defined network; Distributed denial of service; Attack detection;
D O I
10.1038/s41598-024-66907-z
中图分类号
学科分类号
摘要
Due to the large computational overhead, underutilization of features, and high bandwidth consumption in traditional SDN environments for DDoS attack detection and mitigation methods, this paper proposes a two-stage detection and mitigation method for DDoS attacks in SDN based on multi-dimensional characteristics. Firstly, an analysis of the traffic statistics from the SDN switch ports is performed, which aids in conducting a coarse-grained detection of DDoS attacks within the network. Subsequently, a Multi-Dimensional Deep Convolutional Classifier (MDDCC) is constructed using wavelet decomposition and convolutional neural networks to extract multi-dimensional characteristics from the traffic data passing through suspicious switches. Based on these extracted multi-dimensional characteristics, a simple classifier can be employed to accurately detect attack samples. Finally, by integrating graph theory with restrictive strategies, the source of attacks in SDN networks can be effectively traced and isolated. The experimental results indicate that the proposed method, which utilizes a minimal amount of statistical information, can quickly and accurately detect attacks within the SDN network. It demonstrates superior accuracy and generalization capabilities compared to traditional detection methods, especially when tested on both simulated and public datasets. Furthermore, by isolating the affected nodes, the method effectively mitigates the impact of the attacks, ensuring the normal transmission of legitimate traffic during network attacks. This approach not only enhances the detection capabilities but also provides a robust mechanism for containing the spread of cyber threats, thereby safeguarding the integrity and performance of the network.
引用
收藏
相关论文
共 50 条
  • [21] K-DDoS-SDN: A distributed DDoS attacks detection approach for protecting SDN environment
    Kaur, Amandeep
    Krishna, C. Rama
    Patil, Nilesh Vishwasrao
    [J]. CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2024, 36 (03):
  • [22] BSD-Guard: A Collaborative Blockchain-Based Approach for Detection and Mitigation of SDN-Targeted DDoS Attacks
    Jiang, Shanqing
    Yang, Lin
    Gao, Xianming
    Zhou, Yuyang
    Feng, Tao
    Song, Yanbo
    Liu, Kexian
    Cheng, Guang
    [J]. SECURITY AND COMMUNICATION NETWORKS, 2022, 2022
  • [23] Early Detection of DDoS Attacks against SDN Controllers
    Mousavi, Seyed Mohammad
    St-Hilaire, Marc
    [J]. 2015 INTERNATIONAL CONFERENCE ON COMPUTING, NETWORKING AND COMMUNICATIONS (ICNC), 2015, : 77 - 81
  • [24] An RBF-PSO Based Approach for Early Detection of DDoS Attacks in SDN
    Dayal, Neelam
    Srivastava, Shashank
    [J]. 2018 10TH INTERNATIONAL CONFERENCE ON COMMUNICATION SYSTEMS & NETWORKS (COMSNETS), 2018, : 17 - 24
  • [25] Real-Time Detection of DDoS Attacks Based on Random Forest in SDN
    Ma, Ruikui
    Wang, Qiuqian
    Bu, Xiangxi
    Chen, Xuebin
    [J]. APPLIED SCIENCES-BASEL, 2023, 13 (13):
  • [26] Detection of DDoS attacks in SDN-based VANET using optimized TabNet
    Setitra, Mohamed Ali
    Fan, Mingyu
    [J]. COMPUTER STANDARDS & INTERFACES, 2024, 90
  • [27] FlowTrApp: An SDN Based Architecture for DDoS Attack Detection and Mitigation in Data Centers
    Buragohain, Chaitanya
    Medhi, Nabajyoti
    [J]. 2016 3RD INTERNATIONAL CONFERENCE ON SIGNAL PROCESSING AND INTEGRATED NETWORKS (SPIN), 2016, : 525 - 530
  • [28] IoT-Based DDoS Attack Detection and Mitigation Using the Edge of SDN
    Yang, Yinqi
    Wang, Jian
    Zhai, Baoqin
    Liu, Jiqiang
    [J]. CYBERSPACE SAFETY AND SECURITY, PT II, 2019, 11983 : 3 - 17
  • [29] ArOMA: An SDN based, autonomic DDoS mitigation framework
    Sahay, Rishikesh
    Blanc, Gregory
    Zhang, Zonghua
    Debar, Herue
    [J]. COMPUTERS & SECURITY, 2017, 70 : 482 - 499
  • [30] DDoS Attack Detection and Mitigation at SDN Data Plane Layer
    Abdulkarem, Huda Saleh
    Dawod, Ammar
    [J]. 2020 IEEE 2ND GLOBAL POWER, ENERGY AND COMMUNICATION CONFERENCE (IEEE GPECOM2020), 2020, : 322 - 326