DataPlane-ML: An integrated attack detection and mitigation solution for software defined networks

被引:3
|
作者
Carvalho, Ranyelson N. N. [1 ]
Costa, Lucas R. R. [1 ]
Bordim, Jacir L. L. [1 ]
Alchieri, Eduardo A. P. [1 ]
机构
[1] Univ Brasilia, Dept Comp Sci, Brasilia, DF, Brazil
来源
关键词
attack detection; data plane; distributed denial of service; machine learning; mitigation; reputation; software defined network; SYN flood;
D O I
10.1002/cpe.7434
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Software defined network (SDN) is a paradigm that emphasizes the separation of the control plane from the data plane, offering advantages such as flexibility and programmability. However, from a security perspective, SDN also introduces new vulnerabilities due to the communication required between these planes. SYN Flood attacks are typical distributed denial-of-service (DDoS) attacks that especially challenge network administrators since they produce a large volume of semi-open TCP connections to a target, compromising its availability. Most of the current solutions to detect and mitigate these attacks are designed to operate at the control plane, imposing an additional overhead on controller functions. Moreover, traffic-blocking mechanisms, a widely used alternative to protect network resources, have the drawback of restricting legitimate traffic. This work proposes DataPlane-ML, an integrated solution to detect and mitigate DDoS attacks on SDN, acting directly in the data plane. DataPlane-ML uses machine learning techniques for attack detection and a mitigation solution based on the node's reputation to avoid blocking legitimate traffic during an attack. Experimental results show that DataPlane-ML is approximate to 26%$$ \approx 26\% $$ faster than statistical-based solutions for attack detection while presenting better accuracy. Moreover, the DataPlane-ML mitigation solution can preserve more than 95%$$ 95\% $$ of legitimate traffic during an attack.
引用
收藏
页数:21
相关论文
共 50 条
  • [21] Detection and Mitigation of ICMP-based DDoS in Software Defined Networks
    Shehabat, Marah M.
    Shurman, Mohammad M.
    [J]. 2024 15TH INTERNATIONAL CONFERENCE ON INFORMATION AND COMMUNICATION SYSTEMS, ICICS 2024, 2024,
  • [22] Detection and Mitigation of ARP Storm Attacks using Software Defined Networks
    Numan, Munther
    Hashim, Fazirulhisyam
    Latiff, Nurul Adilah Abdul
    [J]. 2017 IEEE 13TH MALAYSIA INTERNATIONAL CONFERENCE ON COMMUNICATIONS (MICC), 2017, : 181 - 186
  • [23] An Evolutionary SVM Model for DDOS Attack Detection in Software Defined Networks
    Sahoo, Kshira Sagar
    Tripathy, Bata Krishna
    Naik, Kshirasagar
    Ramasubbareddy, Somula
    Balusamy, Balamurugan
    Khari, Manju
    Burgos, Daniel
    [J]. IEEE ACCESS, 2020, 8 : 132502 - 132513
  • [24] Edge DDoS Attack Detection Method Based on Software Defined Networks
    Ren, Gangsheng
    Zhang, Yang
    Zhang, Shukui
    Long, Hao
    [J]. ALGORITHMS AND ARCHITECTURES FOR PARALLEL PROCESSING, ICA3PP 2021, PT I, 2022, 13155 : 597 - 611
  • [25] An Evolutionary SVM Model for DDOS Attack Detection in Software Defined Networks
    Sahoo, Kshira Sagar
    Tripathy, Bata Krishna
    Naik, Kshirasagar
    Ramasubbareddy, Somula
    Balusamy, Balamurugan
    Khari, Manju
    Burgos, Daniel
    [J]. IEEE Access, 2020, 8 : 132502 - 132513
  • [26] Collaborative Security Attack Detection in Software-Defined Vehicular Networks
    Kim, Myeongsu
    Jang, Insun
    Choo, Sukjin
    Koo, Jungwoo
    Pack, Sangheon
    [J]. 2017 19TH ASIA-PACIFIC NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM (APNOMS 2017): MANAGING A WORLD OF THINGS, 2017, : 19 - 24
  • [27] FADM: DDoS Flooding Attack Detection and Mitigation System in Software-Defined Networking
    Hu, Dingwen
    Hong, Peilin
    Chen, Yixin
    [J]. GLOBECOM 2017 - 2017 IEEE GLOBAL COMMUNICATIONS CONFERENCE, 2017,
  • [28] Cyberpulse: A Machine Learning Based Link Flooding Attack Mitigation System for Software Defined Networks
    Rasool, Raihan Ur
    Ashraf, Usman
    Ahmed, Khandakar
    Wang, Hua
    Rafique, Wajid
    Anwar, Zahid
    [J]. IEEE ACCESS, 2019, 7 : 34885 - 34899
  • [29] DDoS Attack in Software Defined Networks: A Survey
    XU Xiaoqiong
    YU Hongfang
    YANG Kun
    [J]. ZTE Communications, 2017, 15 (03) : 13 - 19
  • [30] Simulation of DDoS Attack on Software Defined Networks
    Bikbulatov, Timur R.
    Kurochkin, Ilya I.
    [J]. COMPUTATIONAL MECHANICS AND MODERN APPLIED SOFTWARE SYSTEMS (CMMASS'2019), 2019, 2181