A holistic approach to mitigating DoS attacks in SDN networks

被引:14
|
作者
Dridi, Lobna [1 ]
Zhani, Mohamed Faten [1 ]
机构
[1] ETS, Montreal, PQ, Canada
关键词
DoS attacks; IDS accuracy; IDS placement; network security; software-defined networking (SDN); traffic sampling;
D O I
10.1002/nem.1996
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Software-defined networking (SDN) has recently emerged as a new networking technology offering an unprecedented programmability that allows network operators to dynamically manage their infrastructures. However, despite these benefits, deny-of-service (DoS) attacks are considered a major threat to such networks, as they can easily overload the SDN controller and flood switch forwarding tables, resulting in a critical degradation of the network performance. To address this issue, we propose SDN-Guard, a novel holistic approach to protect SDN networks against DoS attacks. Software-defined networking-Guard leverages an intrusion detection system (IDS) to detect potential DoS attacks and then efficiently mitigate their impact by dynamically (1) rerouting malicious traffic, (2) adjusting flow time-outs, and (3) aggregating flow rules. This paper extends our previous work by proposing solutions to minimize the switch-to-IDS traffic without impacting the IDS accuracy. We hence propose to use sampling techniques and devise an integer linear program to find the optimal placement for the IDS and to determine the switches that should mirror the flows towards it so as to minimize network bandwidth consumption. Extensive experiments using Mininet show that SDN-Guard maintains network performance during DoS attacks and succeeds in reducing by up to 32% their impact on controller performance, usage of switch forwarding tables, and control plane bandwidth. Furthermore, our results show that carefully placing the IDS and selecting the switches mirroring, the traffic can reduce by up to 90% the switch-to-IDS traffic. They also show that the IDS accuracy remains at 100% by analyzing only 11% of the network traffic.
引用
收藏
页数:14
相关论文
共 50 条
  • [1] A Scrutinized study on DoS attacks in Wireless Sensor Networks and need of SDN in Mitigating DoS attacks
    Sarkunavathi, A.
    Srinivasan, V
    [J]. 2021 INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATION AND INFORMATICS (ICCCI), 2021,
  • [2] DroPPPP: A P4 Approach to Mitigating DoS Attacks in SDN
    Simsek, Goksel
    Bostan, Hakan
    Sarica, Alper Kaan
    Sarikaya, Egemen
    Keles, Alperen
    Angin, Pelin
    Alemdar, Hande
    Onur, Ertan
    [J]. INFORMATION SECURITY APPLICATIONS, WISA 2019, 2020, 11897 : 55 - 66
  • [3] Mitigating DoS Attacks in SDN Using Offloading Path Strategies
    Huang, Tai-Siang
    Hsiung, Po-Yang
    Cheng, Bo-Chao
    [J]. JOURNAL OF INTERNET TECHNOLOGY, 2019, 20 (04): : 1281 - 1285
  • [4] SDN-Guard: DoS Attacks Mitigation in SDN Networks
    Dridi, Lobna
    Zhani, Mohamed Faten
    [J]. 2016 5TH IEEE INTERNATIONAL CONFERENCE ON CLOUD NETWORKING (IEEE CLOUDNET), 2016, : 212 - 217
  • [5] Mitigating DoS Attacks against SDN Controller Using Information Hiding
    Abdullaziz, Osamah Ibrahiem
    Wang, Li-Chun
    [J]. 2019 IEEE WIRELESS COMMUNICATIONS AND NETWORKING CONFERENCE (WCNC), 2019,
  • [6] Mitigating Denial of Service (DoS) Attacks in OpenFlow Networks
    Oktian, Yustus Eko
    Lee, SangGon
    Lee, HoonJae
    [J]. 2014 INTERNATIONAL CONFERENCE ON INFORMATION AND COMMUNICATION TECHNOLOGY CONVERGENCE (ICTC), 2014, : 325 - 330
  • [7] A Software Approach for Mitigation of DoS Attacks on SDN's (Software-Defined Networks)
    Lotlikar, Trupti
    Shah, Deven
    [J]. SOFT COMPUTING IN DATA ANALYTICS, SCDA 2018, 2019, 758 : 333 - 342
  • [8] Detecting and mitigating DHCP attacks in OpenFlow-based SDN networks: a comprehensive approach
    Aldaoud, Manar
    Al-Abri, Dawood
    Al Maashri, Ahmed
    Kausar, Firdous
    [J]. JOURNAL OF COMPUTER VIROLOGY AND HACKING TECHNIQUES, 2023, 19 (04) : 597 - 614
  • [9] Detecting and mitigating DHCP attacks in OpenFlow-based SDN networks: a comprehensive approach
    Manar Aldaoud
    Dawood Al-Abri
    Ahmed Al Maashri
    Firdous Kausar
    [J]. Journal of Computer Virology and Hacking Techniques, 2023, 19 : 597 - 614
  • [10] Use of Honeypots for Mitigating DoS Attacks targeted on IoT Networks
    Anirudh, M.
    Thileeban, Arul S.
    Nallathambi, Daniel Jeswin
    [J]. 2017 INTERNATIONAL CONFERENCE ON COMPUTER, COMMUNICATION AND SIGNAL PROCESSING (ICCCSP), 2017, : 11 - 14