DDoS Attack Detection in Software Defined Networks by Various Metrics

被引:0
|
作者
Saadallah N.R. [1 ]
Al-Talib S.A.A. [1 ]
Malallah F.L. [1 ]
机构
[1] Computer and Information Department, College of Electronics Engineering, Ninevah University, Mosul
关键词
centralized control networks; controller plane; data plane; detection software; distributed denial of service attack; Software-defined networks;
D O I
10.2174/1872212115666210714143008
中图分类号
学科分类号
摘要
Background: Software-Defined Networks (SDNs) are a new architectural approach to smart centralized control networks that were introduced alongside Open Flow in 2011. SDNs are programmed using software applications that help operators manage the network in a fully consistent and comprehensive way. Centralization in these networks is considered a weakness, especially if it is accessed by a Distributed Denial of Service (DDoS) attack-which is the process of uploading huge floods of various sorts of traffic to a website, from multiple sources, in order to make it and its services inaccessible to users. Methods: In our current research, we will build an SDN through a Mininet virtualization simulator, and by using Python. A DDoS attack will be detected depending on two facts: firstly, Traffic State-which normally sees traffic packets sent at around 30 packets per second (DDoS packets are about 250 packets per second and will completely disrupt the network if the attack persists). Secondly, the number of IP Hits. The method used in the research appears very effective in detecting DDoS, according to the results we have achieved. Results: The proposed performance of the system: The Precision (PREC), Recall (REC), and F-Measure (F1) metrics have been used for assessment. Conclusion: The novelty of the current research lies in the detection of penetration in SDN networks, by calculating the number of hits by the hacker's device and the number of times they enter the main device in the network, in addition to the large amount of data sent by the hacker's device to the network. The experimental results are promising as compared with the datasets like CIC-DoS, CI-CIDS2017, CSE-CIC-IDS2018, and customized dataset. The results ranged between 90% and 96%. © 2022 Bentham Science Publishers.
引用
收藏
相关论文
共 50 条
  • [41] A DDoS attack detection based on deep learning in software-defined Internet of things
    Wang, Jiushuang
    Liu, Ying
    Su, Wei
    Feng, Huifen
    2020 IEEE 92ND VEHICULAR TECHNOLOGY CONFERENCE (VTC2020-FALL), 2020,
  • [42] Detection and Analysis of TCP-SYN DDoS Attack in Software-Defined Networking
    Swami, Rochak
    Dave, Mayank
    Ranga, Virender
    WIRELESS PERSONAL COMMUNICATIONS, 2021, 118 (04) : 2295 - 2317
  • [43] Detection and Analysis of TCP-SYN DDoS Attack in Software-Defined Networking
    Rochak Swami
    Mayank Dave
    Virender Ranga
    Wireless Personal Communications, 2021, 118 : 2295 - 2317
  • [44] Ensemble of deep reinforcement learning with optimization model for DDoS attack detection and classification in cloud based software defined networks
    Paidipati, Kiran Kumar
    Kurangi, Chinnarao
    Uthayakumar, J.
    Padmanayaki, S.
    Pradeepa, D.
    Nithinsha, S.
    MULTIMEDIA TOOLS AND APPLICATIONS, 2024, 83 (11) : 32367 - 32385
  • [45] Ensemble of deep reinforcement learning with optimization model for DDoS attack detection and classification in cloud based software defined networks
    Kiran Kumar Paidipati
    Chinnarao Kurangi
    J. Uthayakumar
    S. Padmanayaki
    D. Pradeepa
    S. Nithinsha
    Multimedia Tools and Applications, 2024, 83 : 32367 - 32385
  • [46] Efficient and Intelligent Attack Detection in Software Defined IoT Networks
    Zhang, Yuntong
    Xu, Jingye
    Wang, Zhiwei
    Geng, Rong
    Choo, Kim-Kwang Raymond
    Arturo Perez-Diaz, Jesus
    Zhu, Dakai
    2020 IEEE INTERNATIONAL CONFERENCE ON EMBEDDED SOFTWARE AND SYSTEMS (ICESS), 2020,
  • [47] Analyzing effective mitigation of DDoS attack with software defined networking
    Dayal, Neelam
    Srivastava, Shashank
    COMPUTERS & SECURITY, 2023, 130
  • [48] SDNTruth: Innovative DDoS Detection Scheme for Software-Defined Networks (SDN)
    Tiago Linhares
    Ahmed Patel
    Ana Luiza Barros
    Marcial Fernandez
    Journal of Network and Systems Management, 2023, 31
  • [49] Toward Network-based DDoS Detection in Software-defined Networks
    Jevtic, Stefan
    Lotfalizadeh, Hamidreza
    Kim, Dongsoo S.
    PROCEEDINGS OF THE 12TH INTERNATIONAL CONFERENCE ON UBIQUITOUS INFORMATION MANAGEMENT AND COMMUNICATION (IMCOM 2018), 2018,
  • [50] SDNTruth: Innovative DDoS Detection Scheme for Software-Defined Networks (SDN)
    Linhares, Tiago
    Patel, Ahmed
    Barros, Ana Luiza
    Fernandez, Marcial
    JOURNAL OF NETWORK AND SYSTEMS MANAGEMENT, 2023, 31 (03)