A comprehensive survey on low-rate and high-rate DDoS defense approaches in SDN: taxonomy, research challenges, and opportunities

被引:2
|
作者
Karnani, Suruchi [1 ]
Agrawal, Neha [2 ]
Kumar, Rohit [3 ]
机构
[1] Amity Univ Gwalior, CSE Dept, Gwalior, Madhya Pradesh, India
[2] Indian Inst Informat Technol Sri City, CSE Grp, Chittoor, Andhra Pradesh, India
[3] Shiv Nadar Univ, CSE Dept, Chennai, Tamil Nadu, India
关键词
Software defined networking; Distributed denial of service attacks; High-rate DDoS (HR-DDoS) attacks; Low-rate DDoS (LR-DDoS) attacks; Defense approaches; Performance metrics; SOFTWARE-DEFINED NETWORKING; ATTACK DETECTION; INTRUSION DETECTION; ANOMALY DETECTION; MITIGATION; SECURITY; MACHINE; COUNTERMEASURE;
D O I
10.1007/s11042-023-16781-0
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Software Defined Networking (SDN) expands the networking capabilities using abstraction, open-source protocols, energy efficiency, and programmable features for controlling the forwarding devices at the network edges and intensifying the network performance. Despite all the unprecedented features, SDN still might get exploited by an attacker to launch Distributed Denial of Service (DDoS) attacks at SDN planes i.e. Application, Control, and Data planes. Substantially, the DDoS attacks have been implemented by sending volumetric malicious traffic to exhaust the targeted resources. Such attacks can be easily observed and detected due to their high packet rates. Thus, now attackers are fascinated by the Low-Rate DDoS (LR-DDoS) attacks. In recent years, many efforts have been devoted to defending against the DDoS attacks in SDN. As the attackers benefit from the programmable nature of SDN, an in-detail review of various DDoS attacks and their corresponding defense approaches are essential. Initially, this paper presents a conceptual architecture of SDN and discusses the vulnerable locations in each plane that are exploited by the attacker for launching the DDoS attacks. Secondly, the work offers a detailed classification of DDoS attacks (HR-DDoS and LR-DDoS) concerning the SDN planes and the corresponding defense solutions. The convergence point of this research work is to discover the related security issues and stimulate the network researchers to counter these issues by employing the respective SDN DDoS defense solutions efficiently. Finally, the work gets concluded with a focus on the respective future challenges.
引用
收藏
页码:35253 / 35306
页数:54
相关论文
共 42 条
  • [1] A comprehensive survey on low-rate and high-rate DDoS defense approaches in SDN: taxonomy, research challenges, and opportunities
    Suruchi Karnani
    Neha Agrawal
    Rohit Kumar
    [J]. Multimedia Tools and Applications, 2024, 83 : 35253 - 35306
  • [2] A comprehensive survey of DDoS defense solutions in SDN: Taxonomy, research challenges, and future directions
    Kaur, Sukhveer
    Kumar, Krishan
    Aggarwal, Naveen
    Singh, Gurdeep
    [J]. COMPUTERS & SECURITY, 2021, 110 (110)
  • [3] Survey on Low-Rate DDoS Attacks, Detection and Defense
    Drinic, Dusan
    Cica, Zoran
    [J]. 2024 23RD INTERNATIONAL SYMPOSIUM INFOTEH-JAHORINA, INFOTEH, 2024,
  • [4] Research on low-rate DDoS attack of SDN network in cloud environment
    Chen X.
    Hua Q.
    Wang Y.
    Ge L.
    Zhu Y.
    [J]. Tongxin Xuebao/Journal on Communications, 2019, 40 (06): : 210 - 222
  • [5] An empirical evaluation of information metrics for low-rate and high-rate DDoS attack detection
    Bhuyan, Monowar H.
    Bhattacharyya, D. K.
    Kalita, J. K.
    [J]. PATTERN RECOGNITION LETTERS, 2015, 51 : 1 - 7
  • [6] Low-Rate DoS Attacks, Detection, Defense, and Challenges: A Survey
    Wu Zhijun
    Li Wenjing
    Liu Liang
    Yue Meng
    [J]. IEEE ACCESS, 2020, 8 : 43920 - 43943
  • [7] A Novel Measure for Low-rate and High-rate DDoS Attack Detection using Multivariate Data Analysis
    Hoque, Nazrul
    Bhattacharyya, Dhruba K.
    Kalita, Jugal K.
    [J]. 2016 8TH INTERNATIONAL CONFERENCE ON COMMUNICATION SYSTEMS AND NETWORKS (COMSNETS), 2016,
  • [8] On the duality between low-rate and high-rate sampling
    Agrell, E
    Hamprecht, FA
    Künsch, HR
    [J]. 2003 IEEE INTERNATIONAL SYMPOSIUM ON INFORMATION THEORY - PROCEEDINGS, 2003, : 211 - 211
  • [9] FFSc: a novel measure for low-rate and high-rate DDoS attack detection using multivariate data analysis
    Hoque, Nazrul
    Bhattacharyya, Dhruba K.
    Kalita, Jugal K.
    [J]. SECURITY AND COMMUNICATION NETWORKS, 2016, 9 (13) : 2032 - 2041
  • [10] EFFECTS OF VARYING SCHEDULES OF TIMEOUT ON HIGH-RATE AND LOW-RATE BEHAVIORS
    CALHOUN, KS
    LIMA, PP
    [J]. JOURNAL OF BEHAVIOR THERAPY AND EXPERIMENTAL PSYCHIATRY, 1977, 8 (02) : 189 - 194