SECOD: SDN sEcure COntrol and Data Plane Algorithm for Detecting and Defending against DoS Attacks

被引:0
|
作者
Wang, Song [1 ]
Chandrasekharan, Sathyanarayanan [1 ]
Gomez, Karina [1 ]
Kandeepan, Sithamparanathan [1 ]
Al-Hourani, Akram [1 ]
Asghar, Muhammad Rizwan [2 ]
Russello, Giovanni [2 ]
Zanna, Paul [3 ]
机构
[1] RMIT Univ, Sch Engn, Melbourne, Vic, Australia
[2] Univ Auckland, Cyber Secur Foundry, Auckland, New Zealand
[3] Northbound Networks, Melbourne, Vic, Australia
关键词
SDN; OpenFlow; Security; DoS Attack;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Although the popularity of Software-Defined Networking (SDN) is increasing, it is also vulnerable to security attacks such as Denial of Service (DoS) attacks. Since in SDN, the control plane is isolated from the data plane, DoS attackers can easily target the control plane to impair the network infrastructure in addition to the data plane to degrade the user's Quality of Service (QoS). In our previous work, we introduced SECO, an SDN Secure Controller algorithm to detect and defend SDN against DoS attacks. Simulation results showed that SECO successfully defends SDN networks from DoS attacks. In this paper, we present SDN sEcure COntrol and Data Plane (SECOD), which is an improved version of SECO. Basically, SECOD introduces new triggers to detect and prevent DoS attacks in both control and data planes. Moreover, SECOD is implemented and tested using SDN-based hardware testbed, OpenFlow-based switch, and RYU controller to capture the dynamics of realistic hardware and software. The results show that SECOD successfully detects and effectively mitigates DoS attacks on SDN networks keeping data plane performance at 99.72% compared to a network not under attack.
引用
收藏
页数:5
相关论文
共 50 条
  • [1] SECO: SDN sEcure COntroller Algorithm for Detecting and Defending Denial of Service Attacks
    Wang, Song
    Chavez, Karina Gomez
    Kandeepan, Sithamparanathan
    2017 5TH INTERNATIONAL CONFERENCE ON INFORMATION AND COMMUNICATION TECHNOLOGY (ICOIC7), 2017,
  • [2] Detecting and Defending Against Controller-to-Switch Loop Attacks in SDN
    Zhang Y.
    Jiang Y.
    Zheng J.
    Pang C.-H.
    Li Q.
    Tien Tzu Hsueh Pao/Acta Electronica Sinica, 2019, 47 (05): : 1146 - 1151
  • [3] Mitigating DDoS Attacks in SDN-Based IoT Networks Leveraging Secure Control and Data Plane Algorithm
    Wang, Song
    Gomez, Karina
    Sithamparanathan, Kandeepan
    Asghar, Muhammad Rizwan
    Russello, Giovanni
    Zanna, Paul
    APPLIED SCIENCES-BASEL, 2021, 11 (03): : 1 - 27
  • [4] Secure the Control System against DoS Attacks: A JDL Data Fusion Method
    Yuan, Yuan
    Sun, Fuchun
    PROCESSING OF 2014 INTERNATIONAL CONFERENCE ON MULTISENSOR FUSION AND INFORMATION INTEGRATION FOR INTELLIGENT SYSTEMS (MFI), 2014,
  • [5] FloodDefender: Protecting Data and Control Plane Resources under SDN-aimed DoS Attacks
    Shang, Gao
    Zhe, Peng
    Bin, Xiao
    Aiqun, Hu
    Kui, Ren
    IEEE INFOCOM 2017 - IEEE CONFERENCE ON COMPUTER COMMUNICATIONS, 2017,
  • [6] Combined Control and Data Plane Robustness of SDN Networks against Malicious Node Attacks
    Santos, Dorabella
    de Sousa, Amaro
    Machuca, Carmen Mas
    2018 14TH INTERNATIONAL CONFERENCE ON NETWORK AND SERVICE MANAGEMENT (CNSM), 2018, : 54 - 62
  • [7] Defending RFID authentication protocols against DoS attacks
    Dang Nguyen Duc
    Kim, Kwangjo
    COMPUTER COMMUNICATIONS, 2011, 34 (03) : 384 - 390
  • [8] An Adversarial DBN-LSTM Method for Detecting and Defending against DDoS Attacks in SDN Environments
    Chen, Lei
    Wang, Zhihao
    Huo, Ru
    Huang, Tao
    ALGORITHMS, 2023, 16 (04)
  • [9] Defending Against SDN Network Topology Poisoning Attacks
    Zheng Z.
    Xu M.
    Li Q.
    Zhang Y.
    Li, Qi (qi.li@sz.tsinghua.edu.cn), 2018, Science Press (55): : 207 - 215
  • [10] Detecting DoS Attacks Based on Multi-Features in SDN
    Yue, Meng
    Wang, Huaiyuan
    Liu, Liang
    Wu, Zhijun
    IEEE ACCESS, 2020, 8 : 104688 - 104700