A comprehensive survey on low-rate and high-rate DDoS defense approaches in SDN: taxonomy, research challenges, and opportunities

被引:2
|
作者
Karnani, Suruchi [1 ]
Agrawal, Neha [2 ]
Kumar, Rohit [3 ]
机构
[1] Amity Univ Gwalior, CSE Dept, Gwalior, Madhya Pradesh, India
[2] Indian Inst Informat Technol Sri City, CSE Grp, Chittoor, Andhra Pradesh, India
[3] Shiv Nadar Univ, CSE Dept, Chennai, Tamil Nadu, India
关键词
Software defined networking; Distributed denial of service attacks; High-rate DDoS (HR-DDoS) attacks; Low-rate DDoS (LR-DDoS) attacks; Defense approaches; Performance metrics; SOFTWARE-DEFINED NETWORKING; ATTACK DETECTION; INTRUSION DETECTION; ANOMALY DETECTION; MITIGATION; SECURITY; MACHINE; COUNTERMEASURE;
D O I
10.1007/s11042-023-16781-0
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Software Defined Networking (SDN) expands the networking capabilities using abstraction, open-source protocols, energy efficiency, and programmable features for controlling the forwarding devices at the network edges and intensifying the network performance. Despite all the unprecedented features, SDN still might get exploited by an attacker to launch Distributed Denial of Service (DDoS) attacks at SDN planes i.e. Application, Control, and Data planes. Substantially, the DDoS attacks have been implemented by sending volumetric malicious traffic to exhaust the targeted resources. Such attacks can be easily observed and detected due to their high packet rates. Thus, now attackers are fascinated by the Low-Rate DDoS (LR-DDoS) attacks. In recent years, many efforts have been devoted to defending against the DDoS attacks in SDN. As the attackers benefit from the programmable nature of SDN, an in-detail review of various DDoS attacks and their corresponding defense approaches are essential. Initially, this paper presents a conceptual architecture of SDN and discusses the vulnerable locations in each plane that are exploited by the attacker for launching the DDoS attacks. Secondly, the work offers a detailed classification of DDoS attacks (HR-DDoS and LR-DDoS) concerning the SDN planes and the corresponding defense solutions. The convergence point of this research work is to discover the related security issues and stimulate the network researchers to counter these issues by employing the respective SDN DDoS defense solutions efficiently. Finally, the work gets concluded with a focus on the respective future challenges.
引用
下载
收藏
页码:35253 / 35306
页数:54
相关论文
共 43 条
  • [21] DyProSD: a dynamic protocol specific defense for high-rate DDoS flooding attacks
    Boro, Debojit
    Bhattacharyya, Dhruba K.
    MICROSYSTEM TECHNOLOGIES-MICRO-AND NANOSYSTEMS-INFORMATION STORAGE AND PROCESSING SYSTEMS, 2017, 23 (03): : 593 - 611
  • [22] Low-rate DDoS attack Detection using Deep Learning for SDN-enabled IoT Networks
    Alashhab, Abdussalam Ahmed
    Zahid, Mohd Soperi Mohd
    Muneer, Amgad
    Abdullahi, Mujaheed
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2022, 13 (11) : 371 - 377
  • [23] Resource-Efficient Low-Rate DDoS Mitigation With Moving Target Defense in Edge Clouds
    Zhou, Yuyang
    Cheng, Guang
    Ouyang, Zhi
    Chen, Zongyao
    IEEE Transactions on Network and Service Management, 2025, 22 (01): : 168 - 186
  • [24] GROWTH IN CHICKEN AFTER HIGH-RATE AND LOW-RATE COBALT-60 GAMMA IRRADIATION
    TYLER, SA
    STEARNER, SP
    RADIATION RESEARCH, 1966, 29 (02) : 257 - &
  • [25] Survey on research and progress of low-rate denial of service attacks
    Yang, J.-H. (yang@cernet.edu.cn), 1600, Chinese Academy of Sciences (25):
  • [26] Low-rate and High-rate Distributed DoS Attack Detection Using Partial Rank Correlation
    Bhuyan, M. H.
    Kalwar, A.
    Goswami, A.
    Bhattacharyya, D. K.
    Kalita, J. K.
    2015 FIFTH INTERNATIONAL CONFERENCE ON COMMUNICATION SYSTEMS AND NETWORK TECHNOLOGIES (CSNT2015), 2015, : 706 - 710
  • [27] A Flexible SDN-Based Architecture for Identifying and Mitigating Low-Rate DDoS Attacks Using Machine Learning
    Arturo Perez-Diaz, Jesus
    Amezcua Valdovinos, Ismael
    Choo, Kim-Kwang Raymond
    Zhu, Dakai
    IEEE ACCESS, 2020, 8 (08): : 155859 - 155872
  • [28] Exploring New Opportunities to Defeat Low-Rate DDoS Attack in Container-Based Cloud Environment
    Li, Zhi
    Jin, Hai
    Zou, Deqing
    Yuan, Bin
    IEEE TRANSACTIONS ON PARALLEL AND DISTRIBUTED SYSTEMS, 2020, 31 (03) : 695 - 706
  • [29] A low-rate DDoS detection and mitigation for SDN using Renyi Entropy with Packet Drop (vol 68, 103212, 2022)
    Ahalawat, Anchal
    Babu, Korra Sathya
    Turuk, Ashok Kumar
    Patel, Sanjeev
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2022, 70
  • [30] Effectiveness of an Entropy-Based Approach for Detecting Low- and High-Rate DDoS Attacks against the SDN Controller: Experimental Analysis
    Aladaileh, Mohammad Adnan
    Anbar, Mohammed
    Hintaw, Ahmed J.
    Hasbullah, Iznan H.
    Bahashwan, Abdullah Ahmed
    Al-Amiedy, Taief Alaa
    Ibrahim, Dyala R.
    APPLIED SCIENCES-BASEL, 2023, 13 (02):