SDNTruth: Innovative DDoS Detection Scheme for Software-Defined Networks (SDN)

被引:8
|
作者
Linhares, Tiago [1 ]
Patel, Ahmed [1 ]
Barros, Ana Luiza [1 ]
Fernandez, Marcial [1 ]
机构
[1] Univ Estadual Ceara UECE, Comp Sci Program, Dr Silas Munguba 1700,60-714-903, Fortaleza, CE, Brazil
关键词
Software Defined Networks (SDN); Network Functions Virtualization (NFV); Distributed Denial of Service (DDoS); Thread mitigation; Entropy; ATTACK DETECTION; INTRUSION DETECTION; MACHINE; ENTROPY; SYSTEM; ARCHITECTURE; DEFENSE;
D O I
10.1007/s10922-023-09741-4
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Software-Defined Networks (SDN) are a trending technology in the modern Internet by splitting control and data planes and using a central controller. An SDN controller provides flexible flow management at wire-speed packet forwarding in the Internet. The centralized control allows to implement detection and mitigation of security attacks inside the SDN controller. Typically, Distributed Denial of Service (DDoS) attacks pose an immense threat to Internet security. However, the prediction and prevention of DDoS attacks in SDN environments are a huge challenge. In this paper, we introduce a mechanism to mitigate DDoS attacks in SDN using statistical analysis and traffic entropy. To validate the proposal, a prototype was built in the Mininet tool. The accuracy and training time were compared against different Machine Learning algorithms. Finally, we expound on the effectiveness and limitation of the proposed solution as well as show our research plans and further research opportunities.
引用
收藏
页数:23
相关论文
共 50 条
  • [41] Quantum-Key-Distribution (QKD) Networks Enabled by Software-Defined Networks (SDN)
    Wang, Hua
    Zhao, Yongli
    Nag, Avishek
    [J]. APPLIED SCIENCES-BASEL, 2019, 9 (10):
  • [42] Software-Defined Networking (SDN): the security review
    Hussein, A.
    Chadad, Louma
    Adalian, Nareg
    Chehab, Ali
    Elhajj, Imad H.
    Kayssi, Ayman
    [J]. Journal of Cyber Security Technology, 2020, 4 (01) : 1 - 66
  • [43] Performance Analysis of Software-Defined Networking (SDN)
    Gelberger, Alexander
    Yemini, Niv
    Giladi, Ran
    [J]. 2013 IEEE 21ST INTERNATIONAL SYMPOSIUM ON MODELING, ANALYSIS & SIMULATION OF COMPUTER AND TELECOMMUNICATION SYSTEMS (MASCOTS 2013), 2013, : 389 - 393
  • [44] TPDD: A Two-Phase DDoS Detection System in Software-Defined Networking
    Shen, Yi
    Wu, Chunming
    Kong, Dezhang
    Yang, Mingliang
    [J]. ICC 2020 - 2020 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2020,
  • [45] A DDoS attack detection based on deep learning in software-defined Internet of things
    Wang, Jiushuang
    Liu, Ying
    Su, Wei
    Feng, Huifen
    [J]. 2020 IEEE 92ND VEHICULAR TECHNOLOGY CONFERENCE (VTC2020-FALL), 2020,
  • [46] FADM: DDoS Flooding Attack Detection and Mitigation System in Software-Defined Networking
    Hu, Dingwen
    Hong, Peilin
    Chen, Yixin
    [J]. GLOBECOM 2017 - 2017 IEEE GLOBAL COMMUNICATIONS CONFERENCE, 2017,
  • [47] An Entropy-Based Distributed DDoS Detection Mechanism in Software-Defined Networking
    Wang, Rui
    Jia, Zhiping
    Ju, Lei
    [J]. 2015 IEEE TRUSTCOM/BIGDATASE/ISPA, VOL 1, 2015, : 310 - 317
  • [48] Detection and Mitigation of DDoS Attacks Using Conditional Entropy in Software-defined Networking
    Xuanyuan, Ming
    Ramsurrun, Visham
    Seeam, Amar
    [J]. 2019 11TH INTERNATIONAL CONFERENCE ON ADVANCED COMPUTING (ICOAC 2019), 2019, : 66 - 71
  • [49] Detection and Analysis of TCP-SYN DDoS Attack in Software-Defined Networking
    Swami, Rochak
    Dave, Mayank
    Ranga, Virender
    [J]. WIRELESS PERSONAL COMMUNICATIONS, 2021, 118 (04) : 2295 - 2317
  • [50] Review on Detection Techniques against DDoS Attacks on a Software-Defined Networking Controller
    Zubaydi, Haider Dhia
    Anbar, Mohammed
    Wey, Chong Yung
    [J]. 2017 PALESTINIAN INTERNATIONAL CONFERENCE ON INFORMATION AND COMMUNICATION TECHNOLOGY (PICICT), 2017, : 10 - 16