On an Integrated Security Framework for Defense Against Various DDoS Attacks in SDN

被引:1
|
作者
Wu, Hao [1 ]
Hou, Aiqin [1 ]
Nie, Weike [1 ]
Wu, Chase [2 ]
机构
[1] Northwest Univ, Sch Informat Sci & Technol, Xian 710127, Shaanxi, Peoples R China
[2] New Jersey Inst Technol, Dept Data Sci, Newark, NJ 07102 USA
关键词
Software-Defined Networking; high-rate DDoS attack; low-rate DDoS attack; Slow-TCAM attack; attack defense;
D O I
10.1109/ICNC57223.2023.10074226
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
As a new network paradigm, software-defined networking (SDN) technology has been increasingly adopted. Unfortunately, SDN-enabled networks are more prone to threats from DDoS attacks than traditional networks due to the nature of centralized management. We propose an integrated defense framework to detect and mitigate various types of DDoS attacks in SDN-enabled networks. The proposed framework deploys two technical modules in the control plane of SDN for defending against high-rate and low-rate DDoS attacks, respectively. The former module consists of three components, which watch out for suspicious traffic, detect attacks using ensemble learning, and intercept malicious packets, respectively. The latter module is designed specifically to defend against the Slow Ternary Content Addressable Memory (TCAM) exhaustion attack (Slow-TCAM) using a new Alleviative Threat for TCAM (ATFT) algorithm. The proposed framework is implemented and tested in simulated networks using Mininet and further evaluated on the CICDDoS2019 dataset. Experimental results illustrate the superior performance of the proposed framework in defending against different types of DDoS attacks in comparison with other state-of-the-art algorithms.
引用
收藏
页码:311 / 317
页数:7
相关论文
共 50 条
  • [1] Implementation of an SDN-based Security Defense Mechanism Against DDoS Attacks
    Lin, Hsiao-Chung
    Wang, Ping
    JOINT 2016 INTERNATIONAL CONFERENCE ON ECONOMICS AND MANAGEMENT ENGINEERING (ICEME 2016) AND INTERNATIONAL CONFERENCE ON ECONOMICS AND BUSINESS MANAGEMENT (EBM 2016), 2016, : 377 - 383
  • [2] Defense Mechanisms Against DDoS Attacks in SDN Environment
    Kalkan, Kubra
    Gur, Gurkan
    Alagoz, Fatih
    IEEE COMMUNICATIONS MAGAZINE, 2017, 55 (09) : 175 - 179
  • [3] SDNShield: NFV-Based Defense Framework Against DDoS Attacks on SDN Control Plane
    Chen, Kuan-Yin
    Liu, Sen
    Xu, Yang
    Siddhrau, Ishant Kumar
    Zhou, Siyu
    Guo, Zehua
    Chao, H. Jonathan
    IEEE-ACM TRANSACTIONS ON NETWORKING, 2022, 30 (01) : 1 - 17
  • [4] SDNScore: A Statistical Defense Mechanism Against DDoS Attacks in SDN Environment
    Kalkan, Kubra
    Gur, Gurkan
    Alagoz, Fatih
    2017 IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATIONS (ISCC), 2017, : 669 - 675
  • [5] An integrated SDN framework for early detection of DDoS attacks in cloud computing
    Songa, Asha Varma
    Karri, Ganesh Reddy
    JOURNAL OF CLOUD COMPUTING-ADVANCES SYSTEMS AND APPLICATIONS, 2024, 13 (01):
  • [6] An integrated SDN framework for early detection of DDoS attacks in cloud computing
    Asha Varma Songa
    Ganesh Reddy Karri
    Journal of Cloud Computing, 13
  • [7] Source-Based Defense Against DDoS Attacks in SDN Based on sFlow and SOM
    Wang, Meng
    Lu, Yiqin
    Qin, Jiancheng
    IEEE ACCESS, 2022, 10 : 2097 - 2116
  • [8] SDNShield: Towards More Comprehensive Defense against DDoS Attacks on SDN Control Plane
    Chen, Kuan-yin
    Junuthula, Anudeep Reddy
    Siddhrau, Ishant Kumar
    Xu, Yang
    Chao, H. Jonathan
    2016 IEEE CONFERENCE ON COMMUNICATIONS AND NETWORK SECURITY (CNS), 2016, : 28 - 36
  • [9] Adversarial Deep Learning approach detection and defense against DDoS attacks in SDN environments
    Novaes, Matheus P.
    Carvalho, Luiz F.
    Lloret, Jaime
    Proenca, Mario Lemes, Jr.
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2021, 125 : 156 - 167
  • [10] Unified defense against DDoS attacks
    Muthuprasanna, M.
    Manimaran, C.
    Wang, Z.
    NETWORKING 2007: AD HOC AND SENSOR NETWORKS, WIRELESS NETWORKS, NEXT GENERATION INTERNET, PROCEEDINGS, 2007, 4479 : 1047 - +