IQR-based approach for DDoS detection and mitigation in SDN

被引:0
|
作者
Rochak Swami [1 ]
Mayank Dave [1 ]
Virender Ranga [2 ]
机构
[1] Department of Computer Engineering, National Institute of Technology
[2] Department of Information Technology, Delhi Technological University
关键词
D O I
暂无
中图分类号
TP393.08 [];
学科分类号
0839 ; 1402 ;
摘要
Software-defined networking(SDN) is a trending networking paradigm that focuses on decoupling of the control logic from the data plane. This decoupling brings programmability and flexibility for the network management by introducing centralized infrastructure. The complete control logic resides in the controller, and thus it becomes the intellectual and most important entity of the SDN infrastructure. With these advantages, SDN faces several security issues in various SDN layers that may prevent the growth and global adoption of this groundbreaking technology. Control plane exhaustion and switch buffer overflow are examples of such security issues. Distributed denial-of-service(DDoS) attacks are one of the most severe attacks that aim to exhaust the controller’s CPU to discontinue the whole functioning of the SDN network. Hence, it is necessary to design a quick as well as accurate detection scheme to detect the attack traffic at an early stage. In this paper, we present a defense solution to detect and mitigate spoofed flooding DDoS attacks. The proposed defense solution is implemented in the SDN controller. The detection method is based on the idea of an statistical measure — Interquartile Range(IQR). For the mitigation purpose, the existing SDN-in-built capabilities are utilized. In this work, the experiments are performed considering the spoofed SYN flooding attack. The proposed solution is evaluated using different performance parameters, i.e., detection time, detection accuracy, packet_in messages, and CPU utilization. The experimental results reveal that the proposed defense solution detects and mitigates the attack effectively in different attack scenarios.
引用
收藏
页码:76 / 87
页数:12
相关论文
共 50 条
  • [1] IQR-based approach for DDoS detection and mitigation in SDN
    Swami, Rochak
    Dave, Mayank
    Ranga, Virender
    [J]. DEFENCE TECHNOLOGY, 2023, 25 : 76 - 87
  • [2] Detection and mitigation of DDoS in SDN
    Pande, Bhavika
    Bhagat, Gargi
    Priya, Shanu
    Agrawal, Himanshu
    [J]. 2018 ELEVENTH INTERNATIONAL CONFERENCE ON CONTEMPORARY COMPUTING (IC3), 2018, : 371 - 373
  • [3] Neural Network-Based Approach for Detection and Mitigation of DDoS Attacks in SDN Environments
    Hannache, Oussama
    Batouche, Mohamed Chaouki
    [J]. INTERNATIONAL JOURNAL OF INFORMATION SECURITY AND PRIVACY, 2020, 14 (03) : 50 - 71
  • [4] A DDoS Detection and Mitigation System Framework Based on Spark and SDN
    Yan, Qiao
    Huang, Wenyao
    [J]. SMART COMPUTING AND COMMUNICATION, SMARTCOM 2016, 2017, 10135 : 350 - 358
  • [5] Time-based DDoS Detection and Mitigation for SDN Controller
    Dharma, I. Gde N.
    Muthohar, M. Fiqri
    Prayuda, Alvin J. D.
    Priagung, K.
    Choi, Deokjai
    [J]. 2015 17TH ASIA-PACIFIC NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM APNOMS, 2015, : 550 - 553
  • [6] DoubleTrApp: A Weak Vertex Cover based DDoS Detection and Mitigation scheme using SDN approach
    Bardalai, Priyanka
    Medhi, Nabajyoti
    Chakraborty, Swarnendu Kumar
    [J]. 13TH IEEE INTERNATIONAL CONFERENCE ON ADVANCED NETWORKS AND TELECOMMUNICATION SYSTEMS (IEEE ANTS), 2019,
  • [7] Detection and Mitigation of DoS and DDoS Attacks in IoT-Based Stateful SDN: An Experimental Approach
    Galeano-Brajones, Jesus
    Carmona-Murillo, Javier
    Valenzuela-Valdes, Juan F.
    Luna-Valero, Francisco
    [J]. SENSORS, 2020, 20 (03)
  • [8] SDN-based detection and mitigation of DDoS attacks on smart homes
    Garba, Usman Haruna
    Toosi, Adel N.
    Pasha, Muhammad Fermi
    Khan, Suleman
    [J]. COMPUTER COMMUNICATIONS, 2024, 221 : 29 - 41
  • [9] DNS Amplification Based DDoS Attacks in SDN Environment: Detection and Mitigation
    Gupta, Vishal
    Kochar, Amrit
    Saharan, Shail
    Kulshrestha, Rakhee
    [J]. 2019 IEEE 4TH INTERNATIONAL CONFERENCE ON COMPUTER AND COMMUNICATION SYSTEMS (ICCCS 2019), 2019, : 473 - 478
  • [10] Cyber-Secure SDN: A CNN-Based Approach for Efficient Detection and Mitigation of DDoS attacks
    Najar, Ashfaq Ahmad
    Naik, S. Manohar
    [J]. COMPUTERS & SECURITY, 2024, 139