Mitigating while Accessing: A Lightweight Defense Framework Against Link Flooding Attacks in SDN

被引:0
|
作者
Sun Hancun [1 ,2 ]
Chen Xu [1 ,3 ]
Luo Yantian [1 ,2 ]
Ge Ning [1 ,2 ]
机构
[1] Department of Electronic Engineering, Tsinghua University
[2] Beijing National Research Center for Information Science and Technology
[3] Naval Research
关键词
D O I
暂无
中图分类号
学科分类号
摘要
Link flooding attack(LFA) is a type of covert distributed denial of service(DDoS) attack.The attack mechanism of LFAs is to flood critical links within the network to cut off the target area from the Internet. Recently, the proliferation of Internet of Things(IoT) has increased the quantity of vulnerable devices connected to the network and has intensified the threat of LFAs. In LFAs, attackers typically utilize low-speed flows that do not reach the victims, making the attack difficult to detect. Traditional LFA defense methods mainly reroute the attack traffic around the congested link, which encounters high complexity and high computational overhead due to the aggregation of massive attack traffic. To address these challenges, we present an LFA defense framework which can mitigate the attack flows at the border switches when they are small in scale. This framework is lightweight and can be deployed at border switches of the network in a distributed manner, which ensures the scalability of our defense system. The performance of our framework is assessed in an experimental environment. The simulation results indicate that our method is effective in detecting and mitigating LFAs with low time complexity.
引用
收藏
页码:15 / 27
页数:13
相关论文
共 50 条
  • [21] SDNShield: NFV-Based Defense Framework Against DDoS Attacks on SDN Control Plane
    Chen, Kuan-Yin
    Liu, Sen
    Xu, Yang
    Siddhrau, Ishant Kumar
    Zhou, Siyu
    Guo, Zehua
    Chao, H. Jonathan
    [J]. IEEE-ACM TRANSACTIONS ON NETWORKING, 2022, 30 (01) : 1 - 17
  • [22] Mitigating Crossfire Attacks using SDN-based Moving Target Defense
    Aydeger, Abdullah
    Saputro, Nico
    Akkaya, Kemal
    Rahman, Mohammad
    [J]. 2016 IEEE 41ST CONFERENCE ON LOCAL COMPUTER NETWORKS (LCN), 2016, : 627 - 630
  • [23] Lightweight Algorithm for Protecting SDN controller against DDoS attacks
    Gkountis, Christos
    Taha, Miran
    Lloret, Jaime
    Kambourakis, Georgios
    [J]. 2017 10TH IFIP WIRELESS AND MOBILE NETWORKING CONFERENCE (WMNC 2017), 2017,
  • [24] Lightweight Coordinated Defence Against Interest Flooding Attacks in NDN
    Salah, Hani
    Wulfheide, Julian
    Strufe, Thorsten
    [J]. 2015 IEEE CONFERENCE ON COMPUTER COMMUNICATIONS WORKSHOPS (INFOCOM WKSHPS), 2015, : 103 - 104
  • [25] Mitigating DoS Attacks against SDN Controller Using Information Hiding
    Abdullaziz, Osamah Ibrahiem
    Wang, Li-Chun
    [J]. 2019 IEEE WIRELESS COMMUNICATIONS AND NETWORKING CONFERENCE (WCNC), 2019,
  • [26] A distributed defense framework for flooding-based DDoS attacks
    You, Yonghua
    Zulkernine, Mohammad
    Haque, Anwar
    [J]. ARES 2008: PROCEEDINGS OF THE THIRD INTERNATIONAL CONFERENCE ON AVAILABILITY, SECURITY AND RELIABILITY, 2008, : 245 - +
  • [27] Fellowship: Defense against Flooding and Packet Drop Attacks in MANET
    Balakrishnan, Venkatesan
    Varadharajan, Vijay
    Tupakula, Udaya Kiran
    [J]. 2006 IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM, VOLS 1 AND 2, 2006, : 1027 - 1030
  • [28] Mitigating HTTP GET Flooding Attacks in SDN Using NetFPGA-based OpenFlow Switch
    An Nguyen Viet
    Luan Phung Van
    Hoang-Anh Nguyen Minh
    Huy Duong Xuan
    Nam Pham Ngoc
    Thanh Nguyen Huu
    [J]. 2017 14TH INTERNATIONAL CONFERENCE ON ELECTRICAL ENGINEERING/ELECTRONICS, COMPUTER, TELECOMMUNICATIONS AND INFORMATION TECHNOLOGY (ECTI-CON), 2017, : 660 - 663
  • [29] ERT-EDR: Online defense framework for LDoS attacks in SDN
    Liu, Boru
    Tang, Dan
    Chen, Jingwen
    Liang, Wei
    Liu, Yufeng
    Yang, Qiuwei
    [J]. EXPERT SYSTEMS WITH APPLICATIONS, 2024, 254
  • [30] RCS: A distributed mechanism against link flooding DDoS attacks
    Cui, Yong
    Song, Lingjian
    Xu, Ke
    [J]. INFORMATION NETWORKING: ADVANCES IN DATA COMMUNICATIONS AND WIRELESS NETWORKS, 2006, 3961 : 764 - +