DataPlane-ML: An integrated attack detection and mitigation solution for software defined networks

被引:3
|
作者
Carvalho, Ranyelson N. N. [1 ]
Costa, Lucas R. R. [1 ]
Bordim, Jacir L. L. [1 ]
Alchieri, Eduardo A. P. [1 ]
机构
[1] Univ Brasilia, Dept Comp Sci, Brasilia, DF, Brazil
来源
关键词
attack detection; data plane; distributed denial of service; machine learning; mitigation; reputation; software defined network; SYN flood;
D O I
10.1002/cpe.7434
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Software defined network (SDN) is a paradigm that emphasizes the separation of the control plane from the data plane, offering advantages such as flexibility and programmability. However, from a security perspective, SDN also introduces new vulnerabilities due to the communication required between these planes. SYN Flood attacks are typical distributed denial-of-service (DDoS) attacks that especially challenge network administrators since they produce a large volume of semi-open TCP connections to a target, compromising its availability. Most of the current solutions to detect and mitigate these attacks are designed to operate at the control plane, imposing an additional overhead on controller functions. Moreover, traffic-blocking mechanisms, a widely used alternative to protect network resources, have the drawback of restricting legitimate traffic. This work proposes DataPlane-ML, an integrated solution to detect and mitigate DDoS attacks on SDN, acting directly in the data plane. DataPlane-ML uses machine learning techniques for attack detection and a mitigation solution based on the node's reputation to avoid blocking legitimate traffic during an attack. Experimental results show that DataPlane-ML is approximate to 26%$$ \approx 26\% $$ faster than statistical-based solutions for attack detection while presenting better accuracy. Moreover, the DataPlane-ML mitigation solution can preserve more than 95%$$ 95\% $$ of legitimate traffic during an attack.
引用
收藏
页数:21
相关论文
共 50 条
  • [1] DDoS Flooding Attack Mitigation in Software Defined Networks
    Mahrach, Safaa
    Haqiq, Abdelkrim
    [J]. INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2020, 11 (01) : 693 - 700
  • [2] DDoS flooding attack mitigation in software defined networks
    Mahrach, Safaa
    Haqiq, Abdelkrim
    [J]. International Journal of Advanced Computer Science and Applications, 2020, 11 (01): : 693 - 700
  • [3] Detection and Mitigation of DoS Attacks in Software Defined Networks
    Gao, Shang
    Peng, Zhe
    Xiao, Bin
    Hu, Aiqun
    Song, Yubo
    Ren, Kui
    [J]. IEEE-ACM TRANSACTIONS ON NETWORKING, 2020, 28 (03) : 1419 - 1433
  • [4] Mitigation and Detection of DDoS Attacks in Software Defined Networks
    Murtuza, Shariq
    Asawa, Krishna
    [J]. 2018 ELEVENTH INTERNATIONAL CONFERENCE ON CONTEMPORARY COMPUTING (IC3), 2018, : 389 - 391
  • [5] WiP: Control Plane Saturation Attack Mitigation in Software Defined Networks
    Hubballi, Neminath
    Patel, Kanishk
    [J]. INFORMATION SYSTEMS SECURITY, ICISS 2022, 2022, 13784 : 235 - 246
  • [6] A Link Fabrication Attack Mitigation Approach (LiFAMA) for Software Defined Networks
    Joseph, Katongole
    Eyobu, Odongo Steven
    Kasyoka, Philemon
    Oyana, Tonny J.
    [J]. ELECTRONICS, 2022, 11 (10)
  • [7] Packet Injection Exploiting Attack and Mitigation in Software-Defined Networks
    Li, Jishuai
    Qin, Sujuan
    Tu, Tengfei
    Zhang, Hua
    Li, Yongsheng
    [J]. APPLIED SCIENCES-BASEL, 2022, 12 (03):
  • [8] Improvement in DDoS attack detection in software defined network using ML algorithm
    Chattopadhyay, Saumitra
    Sahoo, Ashok Kumar
    Jasola, Sanjay
    [J]. JOURNAL OF DISCRETE MATHEMATICAL SCIENCES & CRYPTOGRAPHY, 2023, 26 (07): : 2025 - 2044
  • [9] Collaborative detection and mitigation of DDoS in software-defined networks
    Omer Elsier Tayfour
    Muhammad Nadzir Marsono
    [J]. The Journal of Supercomputing, 2021, 77 : 13166 - 13190
  • [10] Collaborative detection and mitigation of DDoS in software-defined networks
    Tayfour, Omer Elsier
    Marsono, Muhammad Nadzir
    [J]. JOURNAL OF SUPERCOMPUTING, 2021, 77 (11): : 13166 - 13190