Distributed Denial of Service Classification for Software-Defined Networking Using Grammatical Evolution

被引:1
|
作者
Spyrou, Evangelos D. [1 ]
Tsoulos, Ioannis [1 ]
Stylios, Chrysostomos [1 ,2 ]
Davoli, Franco
机构
[1] Univ Ioannina, Dept Informat & Telecommun, Arta 47150, Greece
[2] Athena Res Ctr, Ind Syst Inst, Patras 26504, Greece
关键词
SDN; DDoS; genetic algorithm; grammatical evolution; packet classification;
D O I
10.3390/fi15120401
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Software-Defined Networking (SDN) stands as a pivotal paradigm in network implementation, exerting a profound influence on the trajectory of technological advancement. The critical role of security within SDN cannot be overstated, with distributed denial of service (DDoS) emerging as a particularly disruptive threat, capable of causing large-scale disruptions. DDoS operates by generating malicious traffic that mimics normal network activity, leading to service disruptions. It becomes imperative to deploy mechanisms capable of distinguishing between benign and malicious traffic, serving as the initial line of defense against DDoS challenges. In addressing this concern, we propose the utilization of traffic classification as a foundational strategy for combatting DDoS. By categorizing traffic into malicious and normal streams, we establish a crucial first step in the development of effective DDoS mitigation strategies. The deleterious effects of DDoS extend to the point of potentially overwhelming networked servers, resulting in service failures and SDN server downtimes. To investigate and address this issue, our research employs a dataset encompassing both benign and malicious traffic within the SDN environment. A set of 23 features is harnessed for classification purposes, forming the basis for a comprehensive analysis and the development of robust defense mechanisms against DDoS in SDN. Initially, we compare GenClass with three common classification methods, namely the Bayes, K-Nearest Neighbours (KNN), and Random Forest methods. The proposed solution improves the average class error, demonstrating 6.58% error as opposed to the Bayes method error of 32.59%, KNN error of 18.45%, and Random Forest error of 30.70%. Moreover, we utilize classification procedures based on three methods based on grammatical evolution, which are applied to the aforementioned data. In particular, in terms of average class error, GenClass exhibits 6.58%, while NNC and FC2GEN exhibit average class errors of 12.51% and 15.86%, respectively.
引用
收藏
页数:13
相关论文
共 50 条
  • [1] Distributed Denial of Service Attacks in Software-Defined Networking with Cloud Computing
    Yan, Qiao
    Yu, F. Richard
    [J]. IEEE COMMUNICATIONS MAGAZINE, 2015, 53 (04) : 52 - 59
  • [2] Mitigation of Denial of Service Attacks Using OpenDaylight Application in Software-Defined Networking
    Cajas, Carlos D.
    Budanov, Dmitry O.
    [J]. PROCEEDINGS OF THE 2021 IEEE CONFERENCE OF RUSSIAN YOUNG RESEARCHERS IN ELECTRICAL AND ELECTRONIC ENGINEERING (ELCONRUS), 2021, : 260 - 265
  • [3] Detection Techniques of Distributed Denial of Service Attacks on Software-Defined Networking Controller-A Review
    Aladaileh, Mohammad A.
    Anbar, Mohammed
    Hasbullah, Iznan H.
    Chong, Yung-Wey
    Sanjalawe, Yousef K.
    [J]. IEEE ACCESS, 2020, 8 : 143985 - 143995
  • [4] Amplified Distributed Denial of Service Attack in Software Defined Networking
    Ambrosin, Moreno
    Conti, Mauro
    De Gaspari, Fabio
    Devarajan, Nishanth
    [J]. 2016 8TH IFIP INTERNATIONAL CONFERENCE ON NEW TECHNOLOGIES, MOBILITY AND SECURITY (NTMS), 2016,
  • [5] Distributed Denial of Service (DDoS) Attacks in Software-defined Networks (SDN)
    Chahal, Jasmeen Kaur
    Kaur, Puninder
    Sharma, Avinash
    [J]. 2021 5TH INTERNATIONAL CONFERENCE ON ELECTRICAL, ELECTRONICS, COMMUNICATION, COMPUTER TECHNOLOGIES AND OPTIMIZATION TECHNIQUES (ICEECCOT), 2021, : 291 - 295
  • [6] A Defense Mechanism for Distributed Denial of Service Attack in Software-Defined Networks
    Luo, Shibo
    Wu, Jun
    Li, Jianhua
    Pei, Bei
    [J]. 2015 NINTH INTERNATIONAL CONFERENCE ON FRONTIER OF COMPUTER SCIENCE AND TECHNOLOGY FCST 2015, 2015, : 324 - 328
  • [7] A novel Distributed Denial of Service attack defense scheme for Software-Defined Networking using Packet-In message and frequency domain analysis
    Fouladi, Ramin Fadaei
    Karaçay, Leyli
    Gülen, Utku
    Soykan, Elif Ustundag
    [J]. Computers and Electrical Engineering, 2024, 120
  • [8] Toward secure software-defined networks against distributed denial of service attack
    Kshira Sagar Sahoo
    Sanjaya Kumar Panda
    Sampa Sahoo
    Bibhudatta Sahoo
    Ratnakar Dash
    [J]. The Journal of Supercomputing, 2019, 75 : 4829 - 4874
  • [9] Toward secure software-defined networks against distributed denial of service attack
    Sahoo, Kshira Sagar
    Panda, Sanjaya Kumar
    Sahoo, Sampa
    Sahoo, Bibhudatta
    Dash, Ratnakar
    [J]. JOURNAL OF SUPERCOMPUTING, 2019, 75 (08): : 4829 - 4874
  • [10] Early Detection of Distributed Denial of Service Attack in Era of Software-Defined Network
    Joshi, Bineet Kumar
    Joshi, Nitin
    Joshi, Mahesh Chandra
    [J]. 2018 ELEVENTH INTERNATIONAL CONFERENCE ON CONTEMPORARY COMPUTING (IC3), 2018, : 347 - 349