DDoS Attack Detection in Software Defined Networks by Various Metrics

被引:0
|
作者
Saadallah N.R. [1 ]
Al-Talib S.A.A. [1 ]
Malallah F.L. [1 ]
机构
[1] Computer and Information Department, College of Electronics Engineering, Ninevah University, Mosul
关键词
centralized control networks; controller plane; data plane; detection software; distributed denial of service attack; Software-defined networks;
D O I
10.2174/1872212115666210714143008
中图分类号
学科分类号
摘要
Background: Software-Defined Networks (SDNs) are a new architectural approach to smart centralized control networks that were introduced alongside Open Flow in 2011. SDNs are programmed using software applications that help operators manage the network in a fully consistent and comprehensive way. Centralization in these networks is considered a weakness, especially if it is accessed by a Distributed Denial of Service (DDoS) attack-which is the process of uploading huge floods of various sorts of traffic to a website, from multiple sources, in order to make it and its services inaccessible to users. Methods: In our current research, we will build an SDN through a Mininet virtualization simulator, and by using Python. A DDoS attack will be detected depending on two facts: firstly, Traffic State-which normally sees traffic packets sent at around 30 packets per second (DDoS packets are about 250 packets per second and will completely disrupt the network if the attack persists). Secondly, the number of IP Hits. The method used in the research appears very effective in detecting DDoS, according to the results we have achieved. Results: The proposed performance of the system: The Precision (PREC), Recall (REC), and F-Measure (F1) metrics have been used for assessment. Conclusion: The novelty of the current research lies in the detection of penetration in SDN networks, by calculating the number of hits by the hacker's device and the number of times they enter the main device in the network, in addition to the large amount of data sent by the hacker's device to the network. The experimental results are promising as compared with the datasets like CIC-DoS, CI-CIDS2017, CSE-CIC-IDS2018, and customized dataset. The results ranged between 90% and 96%. © 2022 Bentham Science Publishers.
引用
收藏
相关论文
共 50 条
  • [1] Overview of DDoS Attack Detection in Software-Defined Networks
    Wang, Heyu
    Li, Yixuan
    IEEE ACCESS, 2024, 12 : 38351 - 38381
  • [2] DDoS Attack in Software Defined Networks: A Survey
    XU Xiaoqiong
    YU Hongfang
    YANG Kun
    ZTE Communications, 2017, 15 (03) : 13 - 19
  • [3] Simulation of DDoS Attack on Software Defined Networks
    Bikbulatov, Timur R.
    Kurochkin, Ilya I.
    COMPUTATIONAL MECHANICS AND MODERN APPLIED SOFTWARE SYSTEMS (CMMASS'2019), 2019, 2181
  • [4] Edge DDoS Attack Detection Method Based on Software Defined Networks
    Ren, Gangsheng
    Zhang, Yang
    Zhang, Shukui
    Long, Hao
    ALGORITHMS AND ARCHITECTURES FOR PARALLEL PROCESSING, ICA3PP 2021, PT I, 2022, 13155 : 597 - 611
  • [5] An Evolutionary SVM Model for DDOS Attack Detection in Software Defined Networks
    Sahoo, Kshira Sagar
    Tripathy, Bata Krishna
    Naik, Kshirasagar
    Ramasubbareddy, Somula
    Balusamy, Balamurugan
    Khari, Manju
    Burgos, Daniel
    IEEE ACCESS, 2020, 8 : 132502 - 132513
  • [6] An Evolutionary SVM Model for DDOS Attack Detection in Software Defined Networks
    Sahoo, Kshira Sagar
    Tripathy, Bata Krishna
    Naik, Kshirasagar
    Ramasubbareddy, Somula
    Balusamy, Balamurugan
    Khari, Manju
    Burgos, Daniel
    IEEE Access, 2020, 8 : 132502 - 132513
  • [7] Detection of High Rate DDoS Attack From Flash Events Using Information Metrics in Software Defined Networks
    Sahoo, Kshira Sagar
    Tiwary, Mayank
    Sahoo, Bibhudatta
    2018 10TH INTERNATIONAL CONFERENCE ON COMMUNICATION SYSTEMS & NETWORKS (COMSNETS), 2018, : 421 - 424
  • [8] DDoS Attack Detection Method Based on Improved KNN With the Degree of DDoS Attack in Software-Defined Networks
    Dong, Shi
    Sarem, Mudar
    IEEE ACCESS, 2020, 8 : 5039 - 5048
  • [9] DDoS Flooding Attack Mitigation in Software Defined Networks
    Mahrach, Safaa
    Haqiq, Abdelkrim
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2020, 11 (01) : 693 - 700
  • [10] DDoS Attack Detection Approaches in on Software Defined Network
    Muzafar, Saira
    Jhanjhi, N. Z.
    Khan, Navid Ali
    Ashfaq, Farzeen
    2022 14TH INTERNATIONAL CONFERENCE ON MATHEMATICS, ACTUARIAL SCIENCE, COMPUTER SCIENCE AND STATISTICS (MACS), 2022,