Mitigating while Accessing: A Lightweight Defense Framework Against Link Flooding Attacks in SDN

被引:0
|
作者
Sun Hancun [1 ,2 ]
Chen Xu [1 ,3 ]
Luo Yantian [1 ,2 ]
Ge Ning [1 ,2 ]
机构
[1] Department of Electronic Engineering, Tsinghua University
[2] Beijing National Research Center for Information Science and Technology
[3] Naval Research
关键词
D O I
暂无
中图分类号
学科分类号
摘要
Link flooding attack(LFA) is a type of covert distributed denial of service(DDoS) attack.The attack mechanism of LFAs is to flood critical links within the network to cut off the target area from the Internet. Recently, the proliferation of Internet of Things(IoT) has increased the quantity of vulnerable devices connected to the network and has intensified the threat of LFAs. In LFAs, attackers typically utilize low-speed flows that do not reach the victims, making the attack difficult to detect. Traditional LFA defense methods mainly reroute the attack traffic around the congested link, which encounters high complexity and high computational overhead due to the aggregation of massive attack traffic. To address these challenges, we present an LFA defense framework which can mitigate the attack flows at the border switches when they are small in scale. This framework is lightweight and can be deployed at border switches of the network in a distributed manner, which ensures the scalability of our defense system. The performance of our framework is assessed in an experimental environment. The simulation results indicate that our method is effective in detecting and mitigating LFAs with low time complexity.
引用
收藏
页数:13
相关论文
共 50 条
  • [1] Woodpecker: Detecting and mitigating link-flooding attacks via SDN
    Wang, Lei
    Li, Qing
    Jiang, Yong
    Jia, Xuya
    Wu, Jianping
    [J]. COMPUTER NETWORKS, 2018, 147 : 1 - 13
  • [2] Detecting and Mitigating Target Link-Flooding Attacks Using SDN
    Wang, Juan
    Wen, Ru
    Li, Jiangqi
    Yan, Fei
    Zhao, Bo
    Yu, Fajiang
    [J]. IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2019, 16 (06) : 944 - 956
  • [3] A Novel Framework for Modeling and Mitigating Distributed Link Flooding Attacks
    Liaskos, Christos
    Kotronis, Vasileios
    Dimitropoulos, Xenofontas
    [J]. IEEE INFOCOM 2016 - THE 35TH ANNUAL IEEE INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATIONS, 2016,
  • [4] A Lightweight Compound Defense Framework Against Injection Attacks in IIoT
    Chi, Po-Wen
    Wang, Ming-Hung
    [J]. 2018 IEEE CONFERENCE ON DEPENDABLE AND SECURE COMPUTING (DSC), 2018, : 30 - 37
  • [5] On an Integrated Security Framework for Defense Against Various DDoS Attacks in SDN
    Wu, Hao
    Hou, Aiqin
    Nie, Weike
    Wu, Chase
    [J]. 2023 INTERNATIONAL CONFERENCE ON COMPUTING, NETWORKING AND COMMUNICATIONS, ICNC, 2023, : 311 - 317
  • [6] Centralized defense using smart routing against link-flooding Attacks
    Belabed, Dallal
    Bouet, Mathieu
    Conan, Vania
    [J]. 2018 2ND CYBER SECURITY IN NETWORKING CONFERENCE (CSNET), 2018,
  • [7] Strategic Defense Against Stealthy Link Flooding Attacks: A Signaling Game Approach
    Aydeger, Abdullah
    Manshaei, Mohammad Hossein
    Rahman, Mohammad Ashiqur
    Akkaya, Kemal
    [J]. IEEE TRANSACTIONS ON NETWORK SCIENCE AND ENGINEERING, 2021, 8 (01): : 751 - 764
  • [8] Mitigating Link-Flooding Attack with Segment Rerouting in SDN
    Xie, Lixia
    Ding, Ying
    Yang, Hongyu
    [J]. CYBERSPACE SAFETY AND SECURITY, PT I, 2020, 11982 : 57 - 69
  • [9] New distributed SDN framework for mitigating DDoS attacks
    Alshehhi, Ahmed
    Yeun, Chan Yeob
    Damiani, Ernesto
    [J]. Transactions of the Korean Institute of Electrical Engineers, 2017, 66 (12): : 1913 - 1920
  • [10] CoDef: Collaborative Defense Against Large-Scale Link-Flooding Attacks
    Lee, Soo Bum
    Kang, Min Suk
    Gligor, Virgil D.
    [J]. PROCEEDINGS OF THE 2013 ACM INTERNATIONAL CONFERENCE ON EMERGING NETWORKING EXPERIMENTS AND TECHNOLOGIES (CONEXT '13), 2013, : 417 - 427