Collaborative Defense Against Hybrid Network Attacks by SDN Controllers and P4 Switches

被引:2
|
作者
Wang, You-Chiun [1 ]
Su, Pin-Yu [1 ]
机构
[1] Natl Sun Yat Sen Univ, Dept Comp Sci & Engn, Kaohsiung 80424, Taiwan
关键词
DDoS flood; deep neural network (DNN); hybrid network attack; P4; software-defined networking (SDN); DATA THEFT; CHALLENGES; BOTNET;
D O I
10.1109/TNSE.2023.3324329
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
Software-defined networking (SDN) uses a controller to manage the network. Applying SDN to resist distributed denial-of-service flood (DDoS-F) attacks receives attention. A controller identifies attack flows and gives rules to switches to discard attack packets. Doing so may cause the controller to be busy and impact SDN performance. P4 switches, on the other hand, can recognize DDoS-F attacks without controller involvement. However, some non-DDoS attacks like keylogging and data theft cannot be well identified by P4 switches due to their local views. Thus, the article makes the controller and P4 switches cooperate to defend against hybrid network attacks that include both DDoS-F attacks and non-DDoS attacks. To this end, we propose a collaborative defense by control and data planes (CD2P) framework. P4 switches (i.e., data plane) find DDoS-F packets by using an entropy-aware detection scheme that can adjust thresholds based on the network status. They also report flow information (excluding DDoS-F flows) to the controller. With the deep learning technique, the controller (i.e., control plane) analyzes these reports to discover non-DDoS attacks. Hence, the controller can focus on detecting these attacks without the disturbance of many DDoS-F packets. Experimental results reveal that CD2P can quickly block DDoS-F attacks and better identify keylogging and data theft. Our contribution is to propose a novel framework for the controller and P4 switches to collaborate to defend against hybrid network attacks efficiently.
引用
收藏
页码:1480 / 1495
页数:16
相关论文
共 50 条
  • [1] Synchronizing DDoS defense at network edge with P4, SDN, and Blockchain
    Febro, Aldo
    Xiao, Hannan
    Spring, Joseph
    Christianson, Bruce
    COMPUTER NETWORKS, 2022, 216
  • [2] P4Filter: A two level defensive mechanism against attacks in SDN using P4
    Saxena, Ananya
    Muttreja, Ritvik
    Upadhyay, Shivam
    Kumar, K. Shiv
    Venkanna, U.
    2021 IEEE INTERNATIONAL CONFERENCE ON ADVANCED NETWORKS AND TELECOMMUNICATIONS SYSTEMS (IEEE ANTS), 2021,
  • [3] DroPPPP: A P4 Approach to Mitigating DoS Attacks in SDN
    Simsek, Goksel
    Bostan, Hakan
    Sarica, Alper Kaan
    Sarikaya, Egemen
    Keles, Alperen
    Angin, Pelin
    Alemdar, Hande
    Onur, Ertan
    INFORMATION SECURITY APPLICATIONS, WISA 2019, 2020, 11897 : 55 - 66
  • [4] A Hybrid SDN Switch Based on Standard P4 Code
    Alvarez-Horcajo, Joaquin
    Martinez-Yelmo, Isaias
    Lopez-Pajares, Diego
    Carral, Juan A.
    Savi, Marco
    IEEE COMMUNICATIONS LETTERS, 2021, 25 (05) : 1482 - 1485
  • [5] AID-SDN: Advanced Intelligent Defense for SDN using P4 and Machine Learning
    Nascimento, Adiel
    Abreu, Diego
    Riker, Andre
    Abelem, Antonio
    2023 IEEE LATIN-AMERICAN CONFERENCE ON COMMUNICATIONS, LATINCOM, 2023,
  • [6] Early Detection of DDoS Attacks against SDN Controllers
    Mousavi, Seyed Mohammad
    St-Hilaire, Marc
    2015 INTERNATIONAL CONFERENCE ON COMPUTING, NETWORKING AND COMMUNICATIONS (ICNC), 2015, : 77 - 81
  • [7] Securing Distributed SDN Controllers Against DoS Attacks
    Etaiwi, Wael
    Biltawi, Mariam
    Almajali, Sufyan
    2017 INTERNATIONAL CONFERENCE ON NEW TRENDS IN COMPUTING SCIENCES (ICTCS), 2017, : 203 - 206
  • [8] A collaborative defense mechanism against DDoS attacks for network service continuity
    Park, PyungKoo
    Yoo, Seongmin
    Ryu, Hoyong
    Park, Jaehyung
    Chung, Kyung-Ho
    Ryou, Jaecheol
    ASIA LIFE SCIENCES, 2015, : 93 - 107
  • [9] Defense Mechanisms Against DDoS Attacks in SDN Environment
    Kalkan, Kubra
    Gur, Gurkan
    Alagoz, Fatih
    IEEE COMMUNICATIONS MAGAZINE, 2017, 55 (09) : 175 - 179
  • [10] A protocol for cluster confirmations of SDN controllers against DDoS attacks
    Iranmanesh, Amir
    Naji, Hamid Reza
    COMPUTERS & ELECTRICAL ENGINEERING, 2021, 93