Collaborative Defense Against Hybrid Network Attacks by SDN Controllers and P4 Switches

被引:3
|
作者
Wang, You-Chiun [1 ]
Su, Pin-Yu [1 ]
机构
[1] Natl Sun Yat Sen Univ, Dept Comp Sci & Engn, Kaohsiung 80424, Taiwan
关键词
DDoS flood; deep neural network (DNN); hybrid network attack; P4; software-defined networking (SDN); DATA THEFT; CHALLENGES; BOTNET;
D O I
10.1109/TNSE.2023.3324329
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
Software-defined networking (SDN) uses a controller to manage the network. Applying SDN to resist distributed denial-of-service flood (DDoS-F) attacks receives attention. A controller identifies attack flows and gives rules to switches to discard attack packets. Doing so may cause the controller to be busy and impact SDN performance. P4 switches, on the other hand, can recognize DDoS-F attacks without controller involvement. However, some non-DDoS attacks like keylogging and data theft cannot be well identified by P4 switches due to their local views. Thus, the article makes the controller and P4 switches cooperate to defend against hybrid network attacks that include both DDoS-F attacks and non-DDoS attacks. To this end, we propose a collaborative defense by control and data planes (CD2P) framework. P4 switches (i.e., data plane) find DDoS-F packets by using an entropy-aware detection scheme that can adjust thresholds based on the network status. They also report flow information (excluding DDoS-F flows) to the controller. With the deep learning technique, the controller (i.e., control plane) analyzes these reports to discover non-DDoS attacks. Hence, the controller can focus on detecting these attacks without the disturbance of many DDoS-F packets. Experimental results reveal that CD2P can quickly block DDoS-F attacks and better identify keylogging and data theft. Our contribution is to propose a novel framework for the controller and P4 switches to collaborate to defend against hybrid network attacks efficiently.
引用
收藏
页码:1480 / 1495
页数:16
相关论文
共 50 条
  • [21] Cascaded Look Up Table Distillation of P4 Deep Neural Network Switches
    De Marinis, Lorenzo
    Paolini, Emilio
    Abu Bakar, Rana
    Cugini, Filippo
    Paolucci, Francesco
    IEEE CONFERENCE ON GLOBAL COMMUNICATIONS, GLOBECOM, 2023, : 2111 - 2116
  • [22] On an Integrated Security Framework for Defense Against Various DDoS Attacks in SDN
    Wu, Hao
    Hou, Aiqin
    Nie, Weike
    Wu, Chase
    2023 INTERNATIONAL CONFERENCE ON COMPUTING, NETWORKING AND COMMUNICATIONS, ICNC, 2023, : 311 - 317
  • [23] SDNScore: A Statistical Defense Mechanism Against DDoS Attacks in SDN Environment
    Kalkan, Kubra
    Gur, Gurkan
    Alagoz, Fatih
    2017 IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATIONS (ISCC), 2017, : 669 - 675
  • [24] Cross-layer detection and defence mechanism against DDoS and DRDoS attacks in software-defined networks using P4 switches
    Li, David Chunhu
    Tu, Hsuan-Hao
    Chou, Li-Der
    COMPUTERS & ELECTRICAL ENGINEERING, 2024, 118
  • [25] Runtime Verification of P4 Switches with Reinforcement Learning
    Shukla, Apoory
    Hudemann, Kevin Nico
    Hecker, Artur
    Schmid, Stefan
    NETAI'19: PROCEEDINGS OF THE 2019 ACM SIGCOMM WORKSHOP ON NETWORK MEETS AI & ML, 2019, : 1 - 7
  • [26] Deploying PolKA Source Routing in P4 Switches
    Dominicini, Cristina
    Guimaraes, Rafael
    Mafioletti, Diego
    Martinello, Magnos
    Ribeiro, Moises R. N.
    Villaca, Rodolfo
    Loui, Frederic
    Ortiz, Jordi
    Slyne, Frank
    Ruffini, Marco
    Kenny, Eoin
    2021 INTERNATIONAL CONFERENCE ON OPTICAL NETWORK DESIGN AND MODELLING (ONDM), 2021,
  • [27] Distributed SIP DDoS Defense with P4
    Febro, Aldo
    Xiao, Hannan
    Spring, Joseph
    2019 IEEE WIRELESS COMMUNICATIONS AND NETWORKING CONFERENCE (WCNC), 2019,
  • [28] Adaptive defense against various network attacks
    Zou, Cliff C.
    Duffield, Nick
    Towsley, Don
    Gong, Weibo
    IEEE JOURNAL ON SELECTED AREAS IN COMMUNICATIONS, 2006, 24 (10) : 1877 - 1888
  • [29] Real-time Pipeline Reconfiguration of P4 Programmable Switches to Efficiently Detect and Mitigate DDoS Attacks
    Al Sadi, Amir
    Savi, Marco
    Berardi, Davide
    Melis, Andrea
    Prandini, Marco
    Callegati, Franco
    2023 26TH CONFERENCE ON INNOVATION IN CLOUDS, INTERNET AND NETWORKS AND WORKSHOPS, ICIN, 2023,
  • [30] SWITCHV: Automated SDN Switch Validation with P4 Models
    Albab, Kinan Dak
    DiLorenzo, Jonathan
    Heule, Stefan
    Kheradmand, Ali
    Smolka, Steffen
    Weitz, Konstantin
    Timarzi, Muhammad
    Gao, Jiaqi
    Yu, Minlan
    SIGCOMM '22: PROCEEDINGS OF THE 2022 ACM SIGCOMM 2022 CONFERENCE, 2022, : 365 - 379