FMDADM: A Multi-Layer DDoS Attack Detection and Mitigation Framework Using Machine Learning for Stateful SDN-Based IoT Networks

被引:21
|
作者
Khedr, Walid I. [1 ]
Gouda, Ameer E. [1 ]
Mohamed, Ehab R. [1 ]
机构
[1] Zagazig Univ, Dept Informat Technol, Zagazig 44519, Egypt
关键词
DDoS; detection; IoT; machine learning; mitigation; network security; SDN; SD-IoT; ANOMALY DETECTION;
D O I
10.1109/ACCESS.2023.3260256
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The absence of standards and the diverse nature of the Internet of Things (IoT) have made security and privacy concerns more acute. Attacks such as distributed denial of service (DDoS) are becoming increasingly widespread in IoT, and the need for ways to stop them is growing. The use of newly formed Software-Defined Networking (SDN) significantly lowers the computational burden on IoT network nodes and makes it possible to perform more security measurements. This paper proposes an SDN-based, four module DDoS attack detection and mitigation framework for IoT networks called FMDADM. The proposed FMDADM framework comprises four main modules and five-tier architecture. The first module implements an early detection process based on the average drop rate (ADR) principle using a 32-packet window size. The second module uses a novel double-check mapping function (DCMF), that aids in earlier attack detection at the data plane level. The third module is an ML-based detection application comprising four phases: data preprocessing, feature extraction, training and testing, and classification. This module detects DDoS attacks using only seven features: two selected and five newly computed features. The last module introduces an attack mitigation process. We applied the proposed framework to three test cases: one single-node attack test case and two multi-node attack test cases, all with real IoT traffic generated and deployed in Mininet-IoT. The proposed FMDADM framework efficiently detects DDoS attacks at high and low rates, can discriminate between attack traffic and flash crowds, and protects both local and remote IoT nodes by preventing infection from propagating to the ISP level. The FMDADM outperformed most existing cutting-edge approaches across ten different evaluation criteria. According to the experimental results, FMDADM achieved the following accuracy, precision, F-measure, recall, specificity, negative predictive value, false positive rate, false detection rate, false negative rate, and average detection time benchmarks:-99.79%, 99.43%, 99.77%, 99.79%, 99.95%, 00.21%, 00.91%, 00.23%, and 2.64 mu s, respectively.
引用
下载
收藏
页码:28934 / 28954
页数:21
相关论文
共 50 条
  • [1] A Machine Learning Based Detection and Mitigation of the DDOS Attack by Using SDN Controller Framework
    M. Revathi
    V. V. Ramalingam
    B. Amutha
    Wireless Personal Communications, 2022, 127 (3) : 2417 - 2441
  • [2] A Machine Learning Based Detection and Mitigation of the DDOS Attack by Using SDN Controller Framework
    Revathi, M.
    Ramalingam, V. V.
    Amutha, B.
    WIRELESS PERSONAL COMMUNICATIONS, 2022, 127 (03) : 2417 - 2441
  • [3] DDoS Attack Detection and Mitigation in SDN using Machine Learning
    Khashab, Fatima
    Moubarak, Joanna
    Feghali, Antoine
    Bassil, Carole
    PROCEEDINGS OF THE 2021 IEEE 7TH INTERNATIONAL CONFERENCE ON NETWORK SOFTWARIZATION (NETSOFT 2021): ACCELERATING NETWORK SOFTWARIZATION IN THE COGNITIVE AGE, 2021, : 395 - 401
  • [4] SDN-Based Architecture for Transport and Application Layer DDoS Attack Detection by Using Machine and Deep Learning
    Yungaicela-Naula, Noe Marcelo
    Vargas-Rosales, Cesar
    Perez-Diaz, Jesus Arturo
    IEEE ACCESS, 2021, 9 : 108495 - 108512
  • [5] A DDoS Attack Mitigation Scheme in ISP Networks Using Machine Learning Based on SDN
    Nguyen Ngoc Tuan
    Pham Huy Hung
    Nguyen Danh Nghia
    Nguyen Van Tho
    Trung Van Phan
    Nguyen Huu Thanh
    ELECTRONICS, 2020, 9 (03)
  • [6] IoT-Based DDoS Attack Detection and Mitigation Using the Edge of SDN
    Yang, Yinqi
    Wang, Jian
    Zhai, Baoqin
    Liu, Jiqiang
    CYBERSPACE SAFETY AND SECURITY, PT II, 2019, 11983 : 3 - 17
  • [7] Deep Learning-based Slow DDoS Attack Detection in SDN-based Networks
    Nugraha, Beny
    Murthy, Rathan Narasimha
    2020 IEEE CONFERENCE ON NETWORK FUNCTION VIRTUALIZATION AND SOFTWARE DEFINED NETWORKS (NFV-SDN), 2020, : 51 - 56
  • [8] RMCARTAM For DDoS Attack Mitigation in SDN Using Machine Learning
    Revathi M.
    Ramalingam V.V.
    Amutha B.
    Computer Systems Science and Engineering, 2023, 45 (03): : 3023 - 3036
  • [9] Machine learning based low-rate DDoS attack detection for SDN enabled IoT networks
    Cheng, Haosu
    Liu, Jianwei
    Xu, Tongge
    Ren, Bohan
    Mao, Jian
    Zhang, Wei
    INTERNATIONAL JOURNAL OF SENSOR NETWORKS, 2020, 34 (01) : 56 - 69
  • [10] Physical Assessment of an SDN-Based Security Framework for DDoS Attack Mitigation: Introducing the SDN-SlowRate-DDoS Dataset
    Yungaicela-Naula, Noe M.
    Vargas-Rosales, Cesar
    Perez-Diaz, Jesus Arturo
    Jacob, Eduardo
    Martinez-Cagnazzo, Carlos
    IEEE ACCESS, 2023, 11 : 46820 - 46831