FMDADM: A Multi-Layer DDoS Attack Detection and Mitigation Framework Using Machine Learning for Stateful SDN-Based IoT Networks

被引:21
|
作者
Khedr, Walid I. [1 ]
Gouda, Ameer E. [1 ]
Mohamed, Ehab R. [1 ]
机构
[1] Zagazig Univ, Dept Informat Technol, Zagazig 44519, Egypt
关键词
DDoS; detection; IoT; machine learning; mitigation; network security; SDN; SD-IoT; ANOMALY DETECTION;
D O I
10.1109/ACCESS.2023.3260256
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The absence of standards and the diverse nature of the Internet of Things (IoT) have made security and privacy concerns more acute. Attacks such as distributed denial of service (DDoS) are becoming increasingly widespread in IoT, and the need for ways to stop them is growing. The use of newly formed Software-Defined Networking (SDN) significantly lowers the computational burden on IoT network nodes and makes it possible to perform more security measurements. This paper proposes an SDN-based, four module DDoS attack detection and mitigation framework for IoT networks called FMDADM. The proposed FMDADM framework comprises four main modules and five-tier architecture. The first module implements an early detection process based on the average drop rate (ADR) principle using a 32-packet window size. The second module uses a novel double-check mapping function (DCMF), that aids in earlier attack detection at the data plane level. The third module is an ML-based detection application comprising four phases: data preprocessing, feature extraction, training and testing, and classification. This module detects DDoS attacks using only seven features: two selected and five newly computed features. The last module introduces an attack mitigation process. We applied the proposed framework to three test cases: one single-node attack test case and two multi-node attack test cases, all with real IoT traffic generated and deployed in Mininet-IoT. The proposed FMDADM framework efficiently detects DDoS attacks at high and low rates, can discriminate between attack traffic and flash crowds, and protects both local and remote IoT nodes by preventing infection from propagating to the ISP level. The FMDADM outperformed most existing cutting-edge approaches across ten different evaluation criteria. According to the experimental results, FMDADM achieved the following accuracy, precision, F-measure, recall, specificity, negative predictive value, false positive rate, false detection rate, false negative rate, and average detection time benchmarks:-99.79%, 99.43%, 99.77%, 99.79%, 99.95%, 00.21%, 00.91%, 00.23%, and 2.64 mu s, respectively.
引用
下载
收藏
页码:28934 / 28954
页数:21
相关论文
共 50 条
  • [21] SDN-based In-Band DDoS Detection Using Ensemble Learning Algorithm on IoT Edge
    Zang, Mingyuan
    Zaballa, Eder Ollora
    Dittmann, Lars
    25TH CONFERENCE ON INNOVATION IN CLOUDS, INTERNET AND NETWORKS (ICIN 2022), 2022, : 111 - 115
  • [22] P4-HLDMC: A Novel Framework for DDoS and ARP Attack Detection and Mitigation in SD-IoT Networks Using Machine Learning, Stateful P4, and Distributed Multi-Controller Architecture
    Khedr, Walid I.
    Gouda, Ameer E.
    Mohamed, Ehab R.
    MATHEMATICS, 2023, 11 (16)
  • [23] Detection and mitigation of attacks in SDN-based IoT network using SVM
    Mishra, Shailendra
    INTERNATIONAL JOURNAL OF COMPUTER APPLICATIONS IN TECHNOLOGY, 2021, 65 (03) : 270 - 281
  • [24] An Efficient SDN-Based DDoS Attack Detection and Rapid Response Platform in Vehicular Networks
    Yu, Yao
    Guo, Lei
    Liu, Ye
    Zheng, Jian
    Zong, Yue
    IEEE ACCESS, 2018, 6 : 44570 - 44579
  • [25] First Demonstration of SDN-based Segment Routing in Multi-layer Networks
    Sgambelluri, A.
    Giorgetti, A.
    Cugini, F.
    Bruno, G.
    Lazzeri, F.
    Castoldi, P.
    2015 OPTICAL FIBER COMMUNICATIONS CONFERENCE AND EXHIBITION (OFC), 2015,
  • [26] Mitigate Volumetric DDoS Attack using Machine Learning Algorithm in SDN based IoT Network Environment
    Kumar, J.
    Rose, P. J. Arul Leena
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2023, 14 (01) : 559 - 568
  • [27] Towards a machine learning-based framework for DDOS attack detection in software-defined IoT (SD-IoT) networks
    Bhayo, Jalal
    Shah, Syed Attique
    Hameed, Sufian
    Ahmed, Awais
    Nasir, Jamal
    Draheim, Dirk
    ENGINEERING APPLICATIONS OF ARTIFICIAL INTELLIGENCE, 2023, 123
  • [28] DDoS Attack Detection on IoT Devices Using Machine Learning Techniques
    Kumar, Sunil
    Sahu, Rohit Kumar
    Rudra, Bhawana
    INTELLIGENT SYSTEMS DESIGN AND APPLICATIONS, ISDA 2021, 2022, 418 : 787 - 794
  • [29] Learning-Driven Detection and Mitigation of DDoS Attack in IoT via SDN-Cloud Architecture
    Ravi, Nagarathna
    Shalinie, S. Mercy
    IEEE INTERNET OF THINGS JOURNAL, 2020, 7 (04) : 3559 - 3570
  • [30] DDoS Attack Detection in IoT-Based Networks Using Machine Learning Models: A Survey and Research Directions
    Alahmadi, Amal A.
    Aljabri, Malak
    Alhaidari, Fahd
    Alharthi, Danyah J.
    Rayani, Ghadi E.
    Marghalani, Leena A.
    Alotaibi, Ohoud B.
    Bajandouh, Shurooq A.
    ELECTRONICS, 2023, 12 (14)