FloodDefender: Protecting Data and Control Plane Resources under SDN-aimed DoS Attacks

被引:0
|
作者
Shang, Gao [1 ]
Zhe, Peng [1 ]
Bin, Xiao [1 ]
Aiqun, Hu [2 ]
Kui, Ren [3 ]
机构
[1] Hong Kong Polytech Univ, Dept Comp, Hong Kong, Hong Kong, Peoples R China
[2] Southeast Univ, Sch Informat Sci & Engn, Nanjing, Jiangsu, Peoples R China
[3] Univ Buffalo State Univ New York, Dept Comp Sci & Engn, Buffalo, NY USA
关键词
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
The separated control and data planes in software-defined networking (SDN) with high programmability introduce a more flexible way to manage and control network traffic. However, SDN will experience long packet delay and high packet loss rate when the communication link between two planes is jammed by SDN-aimed DoS attacks with massive table-miss packets. In this paper, we propose FloodDefender, an efficient and protocol-independent defense framework for SDN/OpenFlow networks to mitigate DoS attacks. It stands between the controller platform and other controller apps, and can protect both the data and control plane resources by leveraging three new techniques: table-miss engineering to prevent the communication bandwidth from being exhausted; packet filter to identify attack traffic and save computational resources of the control plane; and flow rule management to eliminate most of useless flow entries in the switch flow table. All designs of FloodDefender conform to the OpenFlow policy, requiring no additional devices. We implement a prototype of FloodDefender and evaluate its performance in both software and hardware environments. Experimental results show that FloodDefender can efficiently mitigate the SDN-aimed DoS attacks, incurring less than 0.5% CPU computation to handle attack traffic, only 18ms packet delay and 5% packet loss rate under attacks.
引用
收藏
页数:9
相关论文
共 50 条
  • [31] A Wireless Control Plane for Deploying SDN in Data Center Networks
    Wei, Xianglin
    Sun, Qin
    2017 17TH IEEE INTERNATIONAL CONFERENCE ON COMMUNICATION TECHNOLOGY (ICCT 2017), 2017, : 981 - 985
  • [32] Behavior Anomaly Detection in SDN Control Plane:A Case Study of Topology Discovery Attacks
    Chou, Li-Der
    Liu, Chien-Chang
    Lai, Meng-Sheng
    Chiu, Kai-Cheng
    Tu, Hsuan-Hao
    Su, Sen
    Lai, Chun-Lin
    Yen, Chia-Kuan
    Tsai, Wei-Hsiang
    2019 10TH INTERNATIONAL CONFERENCE ON INFORMATION AND COMMUNICATION TECHNOLOGY CONVERGENCE (ICTC): ICT CONVERGENCE LEADING THE AUTONOMOUS FUTURE, 2019, : 357 - 362
  • [33] SDNShield: Towards More Comprehensive Defense against DDoS Attacks on SDN Control Plane
    Chen, Kuan-yin
    Junuthula, Anudeep Reddy
    Siddhrau, Ishant Kumar
    Xu, Yang
    Chao, H. Jonathan
    2016 IEEE CONFERENCE ON COMMUNICATIONS AND NETWORK SECURITY (CNS), 2016, : 28 - 36
  • [34] Behavior Anomaly Detection in SDN Control Plane: A Case Study of Topology Discovery Attacks
    Chou, Li-Der
    Liu, Chien-Chang
    Lai, Meng-Sheng
    Chiu, Kai-Cheng
    Tu, Hsuan-Hao
    Su, Sen
    Lai, Chun-Lin
    Yen, Chia-Kuan
    Tsai, Wei-Hsiang
    WIRELESS COMMUNICATIONS & MOBILE COMPUTING, 2020, 2020
  • [35] Observer-Based Control for Networked Control Systems Under Quantization and DoS Attacks
    Zhang, Xiaodan
    Zhang, Cong
    Xiao, Feng
    Wei, Bo
    2022 41ST CHINESE CONTROL CONFERENCE (CCC), 2022, : 4413 - 4418
  • [36] Resilient Control of Networked Control System Under DoS Attacks: A Unified Game Approach
    Yuan, Yuan
    Yuan, Huanhuan
    Guo, Lei
    Yang, Hongjiu
    Sun, Shanlin
    IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2016, 12 (05) : 1786 - 1794
  • [37] Security Control for Uncertain Networked Control Systems under DoS Attacks and Fading Channels
    Chengzhen Gao
    Cheng Tan
    Hongtao Sun
    Mingyue Xiang
    Journal of Beijing Institute of Technology, 2022, (04) : 422 - 430
  • [38] Event-triggered Control for Stochastic Networked Control Systems under DoS Attacks
    Hu, Zenghui
    Mu, Xiaowu
    PROCEEDINGS OF THE 39TH CHINESE CONTROL CONFERENCE, 2020, : 4389 - 4394
  • [39] Security Control for Uncertain Networked Control Systems under DoS Attacks and Fading Channels
    Gao C.
    Tan C.
    Sun H.
    Xiang M.
    Journal of Beijing Institute of Technology (English Edition), 2022, 31 (04): : 422 - 430
  • [40] On the resilience of Autonomous Connected Vehicles Platoon Under DoS Attacks: a predictor-based sampled data control
    Caiazzo, Bianca
    Lui, Dario Giuseppe
    Mungiello, Aniello
    Petrillo, Alberto
    Santini, Stefania
    2023 IEEE 26TH INTERNATIONAL CONFERENCE ON INTELLIGENT TRANSPORTATION SYSTEMS, ITSC, 2023, : 4907 - 4912