SECOD: SDN sEcure COntrol and Data Plane Algorithm for Detecting and Defending against DoS Attacks

被引:0
|
作者
Wang, Song [1 ]
Chandrasekharan, Sathyanarayanan [1 ]
Gomez, Karina [1 ]
Kandeepan, Sithamparanathan [1 ]
Al-Hourani, Akram [1 ]
Asghar, Muhammad Rizwan [2 ]
Russello, Giovanni [2 ]
Zanna, Paul [3 ]
机构
[1] RMIT Univ, Sch Engn, Melbourne, Vic, Australia
[2] Univ Auckland, Cyber Secur Foundry, Auckland, New Zealand
[3] Northbound Networks, Melbourne, Vic, Australia
关键词
SDN; OpenFlow; Security; DoS Attack;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Although the popularity of Software-Defined Networking (SDN) is increasing, it is also vulnerable to security attacks such as Denial of Service (DoS) attacks. Since in SDN, the control plane is isolated from the data plane, DoS attackers can easily target the control plane to impair the network infrastructure in addition to the data plane to degrade the user's Quality of Service (QoS). In our previous work, we introduced SECO, an SDN Secure Controller algorithm to detect and defend SDN against DoS attacks. Simulation results showed that SECO successfully defends SDN networks from DoS attacks. In this paper, we present SDN sEcure COntrol and Data Plane (SECOD), which is an improved version of SECO. Basically, SECOD introduces new triggers to detect and prevent DoS attacks in both control and data planes. Moreover, SECOD is implemented and tested using SDN-based hardware testbed, OpenFlow-based switch, and RYU controller to capture the dynamics of realistic hardware and software. The results show that SECOD successfully detects and effectively mitigates DoS attacks on SDN networks keeping data plane performance at 99.72% compared to a network not under attack.
引用
收藏
页数:5
相关论文
共 50 条
  • [21] Generating extension strategy for mitigation of DoS attacks against SDN controllers
    Xu H.
    Liu X.
    Yang J.
    Ye Z.
    Xu, Hui (xuhui@mail.hbut.edu.cn), 1754, Totem Publishers Ltd (14) : 1754 - 1764
  • [22] Detecting and Defending against Replication Attacks in Wireless Sensor Networks
    Chen, Xiang-yi
    Meng, Li-xia
    Zhan, Yong-zhao
    INTERNATIONAL JOURNAL OF DISTRIBUTED SENSOR NETWORKS, 2013,
  • [23] Detecting and Defending Against Sybil Attacks in Social Networks: An Overview
    Li, Faxin
    Liu, Bo
    Xiao, Zhefeng
    Fu, Yi
    2014 NINTH INTERNATIONAL CONFERENCE ON BROADBAND AND WIRELESS COMPUTING, COMMUNICATION AND APPLICATIONS (BWCCA), 2014, : 104 - 112
  • [24] SDNShield: Towards More Comprehensive Defense against DDoS Attacks on SDN Control Plane
    Chen, Kuan-yin
    Junuthula, Anudeep Reddy
    Siddhrau, Ishant Kumar
    Xu, Yang
    Chao, H. Jonathan
    2016 IEEE CONFERENCE ON COMMUNICATIONS AND NETWORK SECURITY (CNS), 2016, : 28 - 36
  • [25] Filtering spoofed traffic at source end for defending against DoS/DDoS attacks
    Malliga, S.
    Tamilarasi, A.
    Janani, M.
    ICCN: 2008 INTERNATIONAL CONFERENCE ON COMPUTING, COMMUNICATION AND NETWORKING, 2008, : 216 - 220
  • [26] Distributed output feedback fuzzy secure consensus control for nonlinear MASs against DoS attacks
    Zhang, Jun
    Tong, Shaocheng
    Liu, Xiaodong
    Information Sciences, 2025, 689
  • [27] A secure communication model for defending against insider packet dropping attacks
    Zhang Z.-K.
    Wang Y.
    Jisuanji Xuebao/Chinese Journal of Computers, 2010, 33 (10): : 2003 - 2014
  • [28] Defending against code injection attacks using Secure Design Pattern
    Panjiyar, Anivesh
    Sadhya, Debanjan
    2022 29TH ASIA-PACIFIC SOFTWARE ENGINEERING CONFERENCE, APSEC, 2022, : 570 - 571
  • [29] Secure Control Against Replay Attacks
    Mo, Yilin
    Sinopoli, Bruno
    2009 47TH ANNUAL ALLERTON CONFERENCE ON COMMUNICATION, CONTROL, AND COMPUTING, VOLS 1 AND 2, 2009, : 911 - 918
  • [30] A Secure IoT Firmware Update Scheme Against SCPA and DoS Attacks
    Fan, Yan-Hong
    Wang, Mei-Qin
    Li, Yan-Bin
    Hu, Kai
    Li, Mu-Zhou
    JOURNAL OF COMPUTER SCIENCE AND TECHNOLOGY, 2021, 36 (02) : 419 - 433