SDNTruth: Innovative DDoS Detection Scheme for Software-Defined Networks (SDN)

被引:8
|
作者
Linhares, Tiago [1 ]
Patel, Ahmed [1 ]
Barros, Ana Luiza [1 ]
Fernandez, Marcial [1 ]
机构
[1] Univ Estadual Ceara UECE, Comp Sci Program, Dr Silas Munguba 1700,60-714-903, Fortaleza, CE, Brazil
关键词
Software Defined Networks (SDN); Network Functions Virtualization (NFV); Distributed Denial of Service (DDoS); Thread mitigation; Entropy; ATTACK DETECTION; INTRUSION DETECTION; MACHINE; ENTROPY; SYSTEM; ARCHITECTURE; DEFENSE;
D O I
10.1007/s10922-023-09741-4
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Software-Defined Networks (SDN) are a trending technology in the modern Internet by splitting control and data planes and using a central controller. An SDN controller provides flexible flow management at wire-speed packet forwarding in the Internet. The centralized control allows to implement detection and mitigation of security attacks inside the SDN controller. Typically, Distributed Denial of Service (DDoS) attacks pose an immense threat to Internet security. However, the prediction and prevention of DDoS attacks in SDN environments are a huge challenge. In this paper, we introduce a mechanism to mitigate DDoS attacks in SDN using statistical analysis and traffic entropy. To validate the proposal, a prototype was built in the Mininet tool. The accuracy and training time were compared against different Machine Learning algorithms. Finally, we expound on the effectiveness and limitation of the proposed solution as well as show our research plans and further research opportunities.
引用
收藏
页数:23
相关论文
共 50 条
  • [1] SDNTruth: Innovative DDoS Detection Scheme for Software-Defined Networks (SDN)
    Tiago Linhares
    Ahmed Patel
    Ana Luiza Barros
    Marcial Fernandez
    [J]. Journal of Network and Systems Management, 2023, 31
  • [2] Towards an Efficient DDoS Detection Scheme for Software-Defined Networks
    Lima, N. A. S.
    Fernandez, M. P.
    [J]. IEEE LATIN AMERICA TRANSACTIONS, 2018, 16 (08) : 2296 - 2301
  • [3] Distributed Denial of Service (DDoS) Attacks in Software-defined Networks (SDN)
    Chahal, Jasmeen Kaur
    Kaur, Puninder
    Sharma, Avinash
    [J]. 2021 5TH INTERNATIONAL CONFERENCE ON ELECTRICAL, ELECTRONICS, COMMUNICATION, COMPUTER TECHNOLOGIES AND OPTIMIZATION TECHNIQUES (ICEECCOT), 2021, : 291 - 295
  • [4] Collaborative detection and mitigation of DDoS in software-defined networks
    Omer Elsier Tayfour
    Muhammad Nadzir Marsono
    [J]. The Journal of Supercomputing, 2021, 77 : 13166 - 13190
  • [5] Overview of DDoS Attack Detection in Software-Defined Networks
    Wang, Heyu
    Li, Yixuan
    [J]. IEEE ACCESS, 2024, 12 : 38351 - 38381
  • [6] Collaborative detection and mitigation of DDoS in software-defined networks
    Tayfour, Omer Elsier
    Marsono, Muhammad Nadzir
    [J]. JOURNAL OF SUPERCOMPUTING, 2021, 77 (11): : 13166 - 13190
  • [7] Toward Network-based DDoS Detection in Software-defined Networks
    Jevtic, Stefan
    Lotfalizadeh, Hamidreza
    Kim, Dongsoo S.
    [J]. PROCEEDINGS OF THE 12TH INTERNATIONAL CONFERENCE ON UBIQUITOUS INFORMATION MANAGEMENT AND COMMUNICATION (IMCOM 2018), 2018,
  • [8] A comprehensive survey on DDoS detection, mitigation, and defense strategies in software-defined networks
    Jain, Ankit Kumar
    Shukla, Hariom
    Goel, Diksha
    [J]. CLUSTER COMPUTING-THE JOURNAL OF NETWORKS SOFTWARE TOOLS AND APPLICATIONS, 2024, 27 (09): : 13129 - 13164
  • [9] Towards DDoS detection mechanisms in Software-Defined Networking
    Cui, Yunhe
    Qian, Qing
    Guo, Chun
    Shen, Guowei
    Tian, Youliang
    Xing, Huanlai
    Yan, Lianshan
    [J]. JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2021, 190
  • [10] DDoS Attack Detection Method Based on Improved KNN With the Degree of DDoS Attack in Software-Defined Networks
    Dong, Shi
    Sarem, Mudar
    [J]. IEEE ACCESS, 2020, 8 : 5039 - 5048