FMDADM: A Multi-Layer DDoS Attack Detection and Mitigation Framework Using Machine Learning for Stateful SDN-Based IoT Networks

被引:21
|
作者
Khedr, Walid I. [1 ]
Gouda, Ameer E. [1 ]
Mohamed, Ehab R. [1 ]
机构
[1] Zagazig Univ, Dept Informat Technol, Zagazig 44519, Egypt
关键词
DDoS; detection; IoT; machine learning; mitigation; network security; SDN; SD-IoT; ANOMALY DETECTION;
D O I
10.1109/ACCESS.2023.3260256
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The absence of standards and the diverse nature of the Internet of Things (IoT) have made security and privacy concerns more acute. Attacks such as distributed denial of service (DDoS) are becoming increasingly widespread in IoT, and the need for ways to stop them is growing. The use of newly formed Software-Defined Networking (SDN) significantly lowers the computational burden on IoT network nodes and makes it possible to perform more security measurements. This paper proposes an SDN-based, four module DDoS attack detection and mitigation framework for IoT networks called FMDADM. The proposed FMDADM framework comprises four main modules and five-tier architecture. The first module implements an early detection process based on the average drop rate (ADR) principle using a 32-packet window size. The second module uses a novel double-check mapping function (DCMF), that aids in earlier attack detection at the data plane level. The third module is an ML-based detection application comprising four phases: data preprocessing, feature extraction, training and testing, and classification. This module detects DDoS attacks using only seven features: two selected and five newly computed features. The last module introduces an attack mitigation process. We applied the proposed framework to three test cases: one single-node attack test case and two multi-node attack test cases, all with real IoT traffic generated and deployed in Mininet-IoT. The proposed FMDADM framework efficiently detects DDoS attacks at high and low rates, can discriminate between attack traffic and flash crowds, and protects both local and remote IoT nodes by preventing infection from propagating to the ISP level. The FMDADM outperformed most existing cutting-edge approaches across ten different evaluation criteria. According to the experimental results, FMDADM achieved the following accuracy, precision, F-measure, recall, specificity, negative predictive value, false positive rate, false detection rate, false negative rate, and average detection time benchmarks:-99.79%, 99.43%, 99.77%, 99.79%, 99.95%, 00.21%, 00.91%, 00.23%, and 2.64 mu s, respectively.
引用
下载
收藏
页码:28934 / 28954
页数:21
相关论文
共 50 条
  • [31] Low-rate DDoS attack Detection using Deep Learning for SDN-enabled IoT Networks
    Alashhab A.A.
    Zahid M.S.M.
    Muneer A.
    Abdukkahi M.
    International Journal of Advanced Computer Science and Applications, 2022, 13 (11): : 371 - 377
  • [32] DDoS attack detection in SDN: Enhancing entropy-based detection with machine learning
    Santos-Neto, Marcos J.
    Bordim, Jacir L.
    Alchieri, Eduardo A. P.
    Ishikawa, Edison
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2024, 36 (11):
  • [33] Low-rate DDoS attack Detection using Deep Learning for SDN-enabled IoT Networks
    Alashhab, Abdussalam Ahmed
    Zahid, Mohd Soperi Mohd
    Muneer, Amgad
    Abdullahi, Mujaheed
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2022, 13 (11) : 371 - 377
  • [34] SDN-based DDoS Attack Mitigation Scheme using Convolution Recursively Enhanced Self Organizing Maps
    Harikrishna, Pillutla
    Amuthan, A.
    SADHANA-ACADEMY PROCEEDINGS IN ENGINEERING SCIENCES, 2020, 45 (01):
  • [35] A novel DDoS detection method using multi-layer stacking in SDN environment
    Alasali, Tasnim
    Dakkak, Omar
    Computers and Electrical Engineering, 2024, 120
  • [36] BDF-SDN: A Big Data Framework for DDoS Attack Detection in Large-Scale SDN-Based Cloud
    Phuc Trinh Dinh
    Park, Minho
    2021 IEEE CONFERENCE ON DEPENDABLE AND SECURE COMPUTING (DSC), 2021,
  • [37] Effective and Efficient DDoS Attack Detection Using Deep Learning Algorithm, Multi-Layer Perceptron
    Ahmed, Sheeraz
    Khan, Zahoor Ali
    Mohsin, Syed Muhammad
    Latif, Shahid
    Aslam, Sheraz
    Mujlid, Hana
    Adil, Muhammad
    Najam, Zeeshan
    FUTURE INTERNET, 2023, 15 (02):
  • [38] SDN-based DDoS Attack Mitigation Scheme using Convolution Recursively Enhanced Self Organizing Maps
    Pillutla Harikrishna
    A Amuthan
    Sādhanā, 2020, 45
  • [39] Defending SDN-based IoT Networks Against DDoS Attacks Using Markov Decision Process
    Zheng, Jianjun
    Namin, Akbar Siami
    2018 IEEE INTERNATIONAL CONFERENCE ON BIG DATA (BIG DATA), 2018, : 4589 - 4592
  • [40] Classification of IoT based DDoS Attack using Machine Learning Techniques
    Fasih, Muhammad Ashfaq
    Maryam, Malik
    Urooj, Fatima
    Shahzad, Muhammad Khuram
    PROCEEDINGS OF THE 2022 16TH INTERNATIONAL CONFERENCE ON UBIQUITOUS INFORMATION MANAGEMENT AND COMMUNICATION (IMCOM 2022), 2022,