SECOD: SDN sEcure COntrol and Data Plane Algorithm for Detecting and Defending against DoS Attacks

被引:0
|
作者
Wang, Song [1 ]
Chandrasekharan, Sathyanarayanan [1 ]
Gomez, Karina [1 ]
Kandeepan, Sithamparanathan [1 ]
Al-Hourani, Akram [1 ]
Asghar, Muhammad Rizwan [2 ]
Russello, Giovanni [2 ]
Zanna, Paul [3 ]
机构
[1] RMIT Univ, Sch Engn, Melbourne, Vic, Australia
[2] Univ Auckland, Cyber Secur Foundry, Auckland, New Zealand
[3] Northbound Networks, Melbourne, Vic, Australia
关键词
SDN; OpenFlow; Security; DoS Attack;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Although the popularity of Software-Defined Networking (SDN) is increasing, it is also vulnerable to security attacks such as Denial of Service (DoS) attacks. Since in SDN, the control plane is isolated from the data plane, DoS attackers can easily target the control plane to impair the network infrastructure in addition to the data plane to degrade the user's Quality of Service (QoS). In our previous work, we introduced SECO, an SDN Secure Controller algorithm to detect and defend SDN against DoS attacks. Simulation results showed that SECO successfully defends SDN networks from DoS attacks. In this paper, we present SDN sEcure COntrol and Data Plane (SECOD), which is an improved version of SECO. Basically, SECOD introduces new triggers to detect and prevent DoS attacks in both control and data planes. Moreover, SECOD is implemented and tested using SDN-based hardware testbed, OpenFlow-based switch, and RYU controller to capture the dynamics of realistic hardware and software. The results show that SECOD successfully detects and effectively mitigates DoS attacks on SDN networks keeping data plane performance at 99.72% compared to a network not under attack.
引用
收藏
页数:5
相关论文
共 50 条
  • [41] Decentralized Adaptive Fuzzy Secure Control for Nonlinear Uncertain Interconnected Systems Against Intermittent DoS Attacks
    An, Liwei
    Yang, Guang-Hong
    IEEE TRANSACTIONS ON CYBERNETICS, 2019, 49 (03) : 827 - 838
  • [42] Event-Based Secure Consensus Control for Multirobot Systems With Cooperative Localization Against DoS Attacks
    Tasooji, Tohid Kargar
    Khodadadi, Sakineh
    Marquez, Horacio J.
    IEEE-ASME TRANSACTIONS ON MECHATRONICS, 2024, 29 (01) : 715 - 729
  • [43] Defending saturation attacks on SDN controller: A confusable instance analysis-based algorithm
    Ran, Longyan
    Cui, Yunhe
    Guo, Chun
    Qian, Qing
    Shen, Guowei
    Xing, Huanlai
    COMPUTER NETWORKS, 2022, 213
  • [44] A Sampled-Data-Based Secure Control Approach for Networked Control Systems Under Random DoS Attacks
    Wu, Jiancun
    Peng, Chen
    Zhang, Jin
    Tian, Engang
    IEEE TRANSACTIONS ON CYBERNETICS, 2024, 54 (08) : 4841 - 4851
  • [45] RFVIR: A robust federated algorithm defending against Byzantine attacks
    Wang, Yongkang
    Zhai, Di-Hua
    Xia, Yuanqing
    INFORMATION FUSION, 2024, 105
  • [46] Defending against denial of service attacks using secure name resolution.
    Dewan, P
    Dasgupta, P
    Karamcheti, V
    SAM'03: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON SECURITY AND MANAGEMENT, VOLS 1 AND 2, 2003, : 675 - 681
  • [47] Detecting and Mitigating Denial of Service Attacks against the Data Plane in Software Defined Networks
    Durner, Raphael
    Lorenz, Claas
    Wiedemann, Michael
    Kellerer, Wolfgang
    2017 IEEE CONFERENCE ON NETWORK SOFTWARIZATION (IEEE NETSOFT), 2017,
  • [48] Resilient Control for Multiagent Systems With a Sampled-Data Model Against DoS Attacks
    Fang, Fang
    Li, Jiayu
    Liu, Yajuan
    Park, Ju H.
    IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2023, 19 (01) : 780 - 789
  • [49] Credibility-Based Countermeasure Against Slow HTTP DoS Attacks by Using SDN
    Wang, You-Chiun
    Ye, Ren-Xuan
    2021 IEEE 11TH ANNUAL COMPUTING AND COMMUNICATION WORKSHOP AND CONFERENCE (CCWC), 2021, : 890 - 895
  • [50] Control-plane Isolation and Recovery for a Secure SDN Architecture
    Sasaki, Takayuki
    Asoni, Daniele E.
    Perrig, Adrian
    2016 IEEE NETSOFT CONFERENCE AND WORKSHOPS (NETSOFT), 2016, : 459 - 464