Real-Time Monitoring and Mitigation of SDoS Attacks Using the SDN and New Metrics

被引:0
|
作者
Tang, Dan [1 ]
Wang, Siyuan [1 ]
Zhang, Siqi [1 ]
Qin, Zheng [1 ]
Liang, Wei [2 ]
Xiao, Sheng [1 ]
机构
[1] Hunan Univ, Coll Comp Sci & Elect Engn, Changsha 410082, Peoples R China
[2] Hunan Univ Sci & Technol, Sch Comp Sci & Engn, Xiangtan 411199, Peoples R China
基金
中国国家自然科学基金;
关键词
Monitoring; Measurement; Time-frequency analysis; Real-time systems; Hidden Markov models; Feature extraction; Complexity theory; Slow-rate denial-of-service; coefficient of fluctuation; pulse period coefficient; software-defined network; Gaussian mixture model;
D O I
10.1109/TCCN.2023.3306358
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
Slow-rate denial-of-service (SDoS) attacks are a type of denial-of-service (DoS) attacks with a low attack rate. They have a flash-crowd nature and can be well concealed in legitimate traffic, so it is difficult to identify them by anti-DoS mechanisms. Existing solutions have drawbacks such as difficult deployment, poor real-time performance, and poor scalability. We propose a scheme for real-time monitoring and mitigation of SDoS attacks on the basis of a software-defined network (SDN) and new traffic metrics. The new traffic metrics are the coefficient of fluctuation (CoF) and pulse period coefficient (PPC), which can help us identify SDoS attacks in the network and locate the attackers quickly and accurately. Based on the two metrics, the scheme uses a Gaussian mixture model (GMM) to predict and cluster network traffic and obtain attacker IPs. The mitigation module installs flow rules to discard attacking flows. With blacklisting and weighted IPs, the mitigation module reduces the probability of dropping legitimate flows in case of false positives. Experiments show that our scheme is inexpensive to deploy and can identify attacks and locate attackers quickly and accurately. The mitigation strategy can mitigate SDoS attacks within 4 to 6 seconds with high probability.
引用
收藏
页码:1721 / 1733
页数:13
相关论文
共 50 条
  • [1] Real-Time Detection and Mitigation of LDoS Attacks in the SDN Using the HGB-FP Algorithm
    Tang, Dan
    Zhang, Siqi
    Yan, Yudong
    Chen, Jingwen
    Qin, Zheng
    IEEE TRANSACTIONS ON SERVICES COMPUTING, 2022, 15 (06) : 3471 - 3484
  • [2] Detection and Mitigation of Security Attacks using Real Time SDN Analytics
    Veena, S.
    Manju, R.
    2017 INTERNATIONAL CONFERENCE OF ELECTRONICS, COMMUNICATION AND AEROSPACE TECHNOLOGY (ICECA), VOL 2, 2017, : 87 - 93
  • [3] PeakSAX: Real-Time Monitoring and Mitigation System for LDoS Attack in SDN
    Tang, Dan
    Zheng, Zhiqing
    Wang, Xiaocai
    Xiao, Sheng
    Yang, Qiuwei
    IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2023, 20 (03): : 3686 - 3698
  • [4] Real-time anomaly detection and mitigation using streaming telemetry in SDN
    Kurt, Cagdas
    Erdem, O. Ayhan
    TURKISH JOURNAL OF ELECTRICAL ENGINEERING AND COMPUTER SCIENCES, 2020, 28 (05) : 2448 - 2466
  • [5] Real-time anomaly detection and mitigation using streaming telemetry in SDN
    Kurt Ç.
    Ayhan Erdem O.
    Turkish Journal of Electrical Engineering and Computer Sciences, 2020, 28 (05): : 2448 - 2466
  • [6] Real-Time Detection and Mitigation of Distributed Denial of Service (DDoS) Attacks in Software Defined Networking (SDN)
    Lawal, Babatunde Hafis
    At, Nuray
    2018 26TH SIGNAL PROCESSING AND COMMUNICATIONS APPLICATIONS CONFERENCE (SIU), 2018,
  • [7] Real-Time Contrail Monitoring and Mitigation Using CubeSat Constellations
    Pushparaj, Nishanth
    Cormier, Luis
    Cappelletti, Chantal
    Portapas, Vilius
    Atmosphere, 15 (12):
  • [8] Real-Time Detection of DDoS Attacks Based on Random Forest in SDN
    Ma, Ruikui
    Wang, Qiuqian
    Bu, Xiangxi
    Chen, Xuebin
    APPLIED SCIENCES-BASEL, 2023, 13 (13):
  • [9] Real-time Detection, Isolation and Monitoring of Elephant Flows using Commodity SDN System
    Madanapalli, Sharat Chandra
    Lyu, Minzhao
    Kumar, Himal
    Gharakheili, Hassan Habibi
    Sivaraman, Vijay
    NOMS 2018 - 2018 IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM, 2018,
  • [10] Real-Time Rejection and Mitigation of Time Synchronization Attacks on the Global Positioning System
    Khalajmehrabadi, Ali
    Gatsis, Nikolaos
    Akopian, David
    Taha, Ahmad F.
    IEEE TRANSACTIONS ON INDUSTRIAL ELECTRONICS, 2018, 65 (08) : 6425 - 6435