FloodDefender: Protecting Data and Control Plane Resources under SDN-aimed DoS Attacks

被引:0
|
作者
Shang, Gao [1 ]
Zhe, Peng [1 ]
Bin, Xiao [1 ]
Aiqun, Hu [2 ]
Kui, Ren [3 ]
机构
[1] Hong Kong Polytech Univ, Dept Comp, Hong Kong, Hong Kong, Peoples R China
[2] Southeast Univ, Sch Informat Sci & Engn, Nanjing, Jiangsu, Peoples R China
[3] Univ Buffalo State Univ New York, Dept Comp Sci & Engn, Buffalo, NY USA
关键词
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
The separated control and data planes in software-defined networking (SDN) with high programmability introduce a more flexible way to manage and control network traffic. However, SDN will experience long packet delay and high packet loss rate when the communication link between two planes is jammed by SDN-aimed DoS attacks with massive table-miss packets. In this paper, we propose FloodDefender, an efficient and protocol-independent defense framework for SDN/OpenFlow networks to mitigate DoS attacks. It stands between the controller platform and other controller apps, and can protect both the data and control plane resources by leveraging three new techniques: table-miss engineering to prevent the communication bandwidth from being exhausted; packet filter to identify attack traffic and save computational resources of the control plane; and flow rule management to eliminate most of useless flow entries in the switch flow table. All designs of FloodDefender conform to the OpenFlow policy, requiring no additional devices. We implement a prototype of FloodDefender and evaluate its performance in both software and hardware environments. Experimental results show that FloodDefender can efficiently mitigate the SDN-aimed DoS attacks, incurring less than 0.5% CPU computation to handle attack traffic, only 18ms packet delay and 5% packet loss rate under attacks.
引用
收藏
页数:9
相关论文
共 50 条
  • [21] Data-Driven Containment Control for Unknown MIMO Nonlinear MASs Under Aperiodic DoS Attacks
    Tan, Wen
    Hou, Zhongsheng
    Li, Yuan-Xin
    IEEE TRANSACTIONS ON AUTOMATION SCIENCE AND ENGINEERING, 2024,
  • [22] Data-Driven-Based Distributed Fuzzy Tracking Control for Nonlinear MASs Under DoS Attacks
    Deng, Chao
    Meng, Fanzhi
    Xie, Xiangpeng
    Yue, Dong
    Che, Wei-Wei
    Fan, Sha
    IEEE TRANSACTIONS ON FUZZY SYSTEMS, 2024, 32 (01) : 53 - 63
  • [23] Data Fusion-based Resilient Control System under DoS Attacks: A Game Theoretic Approach
    Yuan, Yuan
    Sun, Fuchun
    INTERNATIONAL JOURNAL OF CONTROL AUTOMATION AND SYSTEMS, 2015, 13 (03) : 513 - 520
  • [24] Stabilization of Networked Control Systems Under DoS Attacks and Output Quantization
    Wakaiki, Masashi
    Cetinkaya, Ahmet
    Ishii, Hideaki
    IEEE TRANSACTIONS ON AUTOMATIC CONTROL, 2020, 65 (08) : 3560 - 3575
  • [25] Optimal Bipartite Tracking Control for Heterogeneous Systems under DoS Attacks
    Yang Y.
    Shi P.
    Lim C.P.
    Chambers J.
    IEEE Transactions on Network and Service Management, 2024, 21 (05): : 1 - 1
  • [26] Validation of Distributed SDN Control Plane Under Uncertain Failures
    Xie, Junjie
    Guo, Deke
    Qian, Chen
    Liu, Lei
    Ren, Bangbang
    Chen, Honghui
    IEEE-ACM TRANSACTIONS ON NETWORKING, 2019, 27 (03) : 1234 - 1247
  • [27] Asynchronous Control of Markov Jump Systems Under Aperiodic DoS Attacks
    Zhang, Yifang
    Wu, Zheng-Guang
    IEEE TRANSACTIONS ON CIRCUITS AND SYSTEMS II-EXPRESS BRIEFS, 2023, 70 (02) : 685 - 689
  • [28] Cyber-Resilient Control of an Islanded Microgrid Under Latency Attacks and Random DoS Attacks
    Yao, Weitao
    Wang, Yu
    Xu, Yan
    Deng, Chao
    IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2023, 19 (04) : 5858 - 5869
  • [29] The Resources Placement Problem in a 5G Hierarchical SDN Control Plane
    Leyva-Pupo, Irian
    Cervello-Pastor, Cristina
    Llorens-Carrodeguas, Alejandro
    DISTRIBUTED COMPUTING AND ARTIFICIAL INTELLIGENCE, 2019, 801 : 370 - 373
  • [30] Automation of Modular and Programmable Control and Data Plane SDN Networks
    Zaballa, Eder Ollora
    Franco, David
    Jacob, Eduardo
    Higuero, Marivi
    Berger, Michael Stubert
    PROCEEDINGS OF THE 2021 17TH INTERNATIONAL CONFERENCE ON NETWORK AND SERVICE MANAGEMENT (CNSM 2021): SMART MANAGEMENT FOR FUTURE NETWORKS AND SERVICES, 2021, : 375 - 379