Detection and mitigation of link flooding-based DDoS attacks on a software defined network using network function virtualisation

被引:0
|
作者
Murtuza, Shariq [1 ]
Asawa, Krishna [1 ]
机构
[1] Jaypee Inst Informat Technol, Dept Comp Sci & Engn & Informat Technol, Noida, India
关键词
software defined networks; SDNs; network function virtualisation; NFV; denial of service attacks; DDoS; virtual network functions; VNFs; VIRTUALIZATION;
D O I
10.1504/IJCNDS.2024.137056
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Software defined networks (SDNs) are emerging as the first choice for network administrators due to their agility, modularity and dynamism. Network operators can change the network topology, routes and other parameters as per their current requirement. Like traditional computer networks SDNs are also prone to various denial of service attacks (DDoS). Link flooding attacks are a class of DDoS attack that aims to choke crucial network connections and can fully detach the victim from the network. In this paper we have discussed two link flooding-based denial of service attacks, namely Coremelt and Crossfire, in the context of SDN along with the possible mitigation. These attacks are aimed at disconnecting services from the network. We demonstrate the usage of network function virtualisation along with SDN features to mitigate these attacks by recreating replicas of the services under attack and connecting them to the network.
引用
收藏
页码:202 / 226
页数:26
相关论文
共 50 条
  • [1] A survey of link flooding attacks in software defined network ecosystems
    Rasool, Raihan Ur
    Wang, Hua
    Ashraf, Usman
    Ahmed, Khandakar
    Anwar, Zahid
    Rafique, Wajid
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2020, 172 (172)
  • [2] Trends on virtualisation with software defined networking and network function virtualisation
    Barona Lopez, Lorena Isabel
    Valdivieso Caraguay, Angel Leonardo
    Garcia Villalba, Luis Javier
    Lopez, Diego
    IET NETWORKS, 2015, 4 (05) : 255 - 263
  • [3] Mitigation and Detection of DDoS Attacks in Software Defined Networks
    Murtuza, Shariq
    Asawa, Krishna
    2018 ELEVENTH INTERNATIONAL CONFERENCE ON CONTEMPORARY COMPUTING (IC3), 2018, : 389 - 391
  • [4] Early Detection of DDoS Attacks Against Software Defined Network Controllers
    Mousavi, Seyed Mohammad
    St-Hilaire, Marc
    JOURNAL OF NETWORK AND SYSTEMS MANAGEMENT, 2018, 26 (03) : 573 - 591
  • [5] Early Detection of DDoS Attacks Against Software Defined Network Controllers
    Seyed Mohammad Mousavi
    Marc St-Hilaire
    Journal of Network and Systems Management, 2018, 26 : 573 - 591
  • [6] MSIDN: Mitigation of Sophisticated Interest flooding-based DDoS attacks in Named Data Networking
    Benmoussa, Ahmed
    Tahari, Abdou el Karim
    Kerrache, Chaker Abdelaziz
    Lagraa, Nasreddine
    Lakas, Abderrahmane
    Hussain, Rasheed
    Ahmad, Farhan
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2020, 107 : 293 - 306
  • [7] Optimized deep neural network based DDoS attack detection and bait mitigation process in software defined network
    Perumal, Karthika
    Arockiasamy, Karmel
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2023, 35 (12):
  • [8] Early Prevention and Mitigation of Link Flooding Attacks in Software Defined Networks
    Murtuza, Shariq
    Asawa, Krishna
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2024, 224
  • [9] Improved Network Monitoring Using Software-Defined Networking for DDoS Detection and Mitigation Evaluation
    J. Ramprasath
    V. Seethalakshmi
    Wireless Personal Communications, 2021, 116 : 2743 - 2757
  • [10] Federated Learning Based DDoS Attacks Detection in Large Scale Software-Defined Network
    Fotse, Yannis Steve Nsuloun
    Tchendji, Vianney Kengne
    Velempini, Mthulisi
    IEEE TRANSACTIONS ON COMPUTERS, 2025, 74 (01) : 101 - 115