Early detection and mitigation of TCP SYN flood attacks in SDN using chi-square test

被引:1
|
作者
Shalini, P. V. [1 ,2 ,3 ]
Radha, V. [3 ]
Sanjeevi, Sriram G. [1 ]
机构
[1] Natl Inst Technol Warangal, Hyderabad, India
[2] Inst Dev & Res Banking Technol, Hyderabad, India
[3] Inst Dev & Res Banking Technol, Ctr Cloud Comp, Hyderabad, India
来源
JOURNAL OF SUPERCOMPUTING | 2023年 / 79卷 / 09期
关键词
DDoS; SDN; Chi-square; TCP SYN flood;
D O I
10.1007/s11227-023-05057-x
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Software Defined Networking (SDN) is a network paradigm with the separation of the control plane from the data plane. Centralized management of the network and dynamic programming ability are the advantages of this separation. However, SDN suffers from security threats like DDoS attacks. In this paper, we propose an early detection and mitigation model to detect the DDoS attacks caused by the TCP SYN flood. This model uses the programming ability of SDN to collect features from net-work traffic at the centralized controller. For that, we implement the proposed model as a module in the POX controller. Our model extracts the header features: MAC addresses and TCP flags to construct the list of number of half-open connections per each host in the network within a given time period. The extended chi-square goodness of fit test serves as a basis for the detection method in our model. We calculate the x(2) value for the list of half-open connections and from this p_value is derived. When p_value drops below the threshold value, the attack is detected. We also mitigate the attack by blocking the attack traffic from the attackers' within the network using source MAC addresses. The experiments results show that the model is successful in TCP SYN flood detection and mitigation at the source end, i.e. attack-originating network. We compare our model with existing literature and show improvement over attack detection and discuss the advantages of the proposed model over the existing schemes in the literature.
引用
收藏
页码:10353 / 10385
页数:33
相关论文
共 50 条
  • [1] Early detection and mitigation of TCP SYN flood attacks in SDN using chi-square test
    P. V. Shalini
    V. Radha
    Sriram G. Sanjeevi
    The Journal of Supercomputing, 2023, 79 : 10353 - 10385
  • [2] SAFETY: Early Detection and Mitigation of TCP SYN Flood Utilizing Entropy in SDN
    Kumar, Prashant
    Tripathi, Meenakshi
    Nehra, Ajay
    Conti, Mauro
    Lal, Chhagan
    IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2018, 15 (04): : 1545 - 1559
  • [3] AEGIS: Detection and Mitigation of TCP SYN Flood on SDN Controller
    Ravi, Nagarathna
    Shalinie, S. Mercy
    Lal, Chhagan
    Conti, Mauro
    IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2021, 18 (01): : 745 - 759
  • [4] DiDDeM: A system for early detection of TCP SYN flood attacks
    Haggerty, J
    Berry, T
    Shi, Q
    Merabti, M
    GLOBECOM '04: IEEE GLOBAL TELECOMMUNICATIONS CONFERENCE, VOLS 1-6, 2004, : 2037 - 2042
  • [5] Detection of insertional covert channels using chi-square test
    College of Computer Science, Zhejiang University, Hang Zhou, China
    不详
    Int. Conf. Multimedia Inf. Networking Secur., MINES, 1600, (432-435):
  • [6] Detection of Insertional Covert Channels Using Chi-square Test
    Cai Zhiyong
    Shen Ying
    Shen Changxiang
    MINES 2009: FIRST INTERNATIONAL CONFERENCE ON MULTIMEDIA INFORMATION NETWORKING AND SECURITY, VOL 1, PROCEEDINGS, 2009, : 432 - +
  • [7] A Robust TCP-SYN Flood Mitigation Scheme Using Machine Learning Based on SDN
    Nguyen Ngoc Tuan
    Pham Huy Hung
    Nguyen Danh Nghia
    Nguyen Van Tho
    Trung V. Phan
    Nguyen Huu Thanh
    2019 10TH INTERNATIONAL CONFERENCE ON INFORMATION AND COMMUNICATION TECHNOLOGY CONVERGENCE (ICTC): ICT CONVERGENCE LEADING THE AUTONOMOUS FUTURE, 2019, : 363 - 368
  • [8] Detecting DoS and DDoS Attacks using Chi-Square
    Leu, Fang-Yei
    Pai, Chia-Chi
    FIFTH INTERNATIONAL CONFERENCE ON INFORMATION ASSURANCE AND SECURITY, VOL 2, PROCEEDINGS, 2009, : 255 - 258
  • [9] Distributed Detection System Using Wavelet Decomposition and Chi-Square Test
    Ouerfelli, Fatima Ezzahra
    Barbaria, Khaled
    Zouari, Belhassen
    Fachkha, Claude
    RISKS AND SECURITY OF INTERNET AND SYSTEMS (CRISIS 2019), 2020, 12026 : 365 - 377
  • [10] SDN-Based SYN ProxyA Solution to Enhance Performance of Attack Mitigation Under TCP SYN Flood
    Dang Van Tuyen
    Truong Thu Huong
    Nguyen Huu Thanh
    Pham Ngoc Nam
    Nguyen Ngoc Thanh
    Marshall, Alan
    COMPUTER JOURNAL, 2019, 62 (04): : 518 - 534