FloodDefender: Protecting Data and Control Plane Resources under SDN-aimed DoS Attacks

被引:0
|
作者
Shang, Gao [1 ]
Zhe, Peng [1 ]
Bin, Xiao [1 ]
Aiqun, Hu [2 ]
Kui, Ren [3 ]
机构
[1] Hong Kong Polytech Univ, Dept Comp, Hong Kong, Hong Kong, Peoples R China
[2] Southeast Univ, Sch Informat Sci & Engn, Nanjing, Jiangsu, Peoples R China
[3] Univ Buffalo State Univ New York, Dept Comp Sci & Engn, Buffalo, NY USA
关键词
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
The separated control and data planes in software-defined networking (SDN) with high programmability introduce a more flexible way to manage and control network traffic. However, SDN will experience long packet delay and high packet loss rate when the communication link between two planes is jammed by SDN-aimed DoS attacks with massive table-miss packets. In this paper, we propose FloodDefender, an efficient and protocol-independent defense framework for SDN/OpenFlow networks to mitigate DoS attacks. It stands between the controller platform and other controller apps, and can protect both the data and control plane resources by leveraging three new techniques: table-miss engineering to prevent the communication bandwidth from being exhausted; packet filter to identify attack traffic and save computational resources of the control plane; and flow rule management to eliminate most of useless flow entries in the switch flow table. All designs of FloodDefender conform to the OpenFlow policy, requiring no additional devices. We implement a prototype of FloodDefender and evaluate its performance in both software and hardware environments. Experimental results show that FloodDefender can efficiently mitigate the SDN-aimed DoS attacks, incurring less than 0.5% CPU computation to handle attack traffic, only 18ms packet delay and 5% packet loss rate under attacks.
引用
收藏
页数:9
相关论文
共 50 条
  • [41] Data-driven adaptive trajectory tracking control of unmanned marine vehicles under disturbances and DoS attacks
    Liu, Huiying
    Hao, Li-Ying
    Liu, Yanli
    Weng, Yongpeng
    INTERNATIONAL JOURNAL OF ROBUST AND NONLINEAR CONTROL, 2024, 34 (02) : 1217 - 1237
  • [42] Observer-Based Secure Control for Vehicular Platooning Under DoS Attacks
    Khodadadi, Sakineh
    Tasooji, Tohid Kargar
    Marquez, Horacio J.
    IEEE ACCESS, 2023, 11 : 20542 - 20552
  • [43] Reference tracking control for cyber-physical systems under DoS attacks
    Oliveira, Pedro M.
    Pessim, Paulo S. P.
    Palma, Jonathan M.
    Lacerda, Marcio J.
    2021 IEEE CHILEAN CONFERENCE ON ELECTRICAL, ELECTRONICS ENGINEERING, INFORMATION AND COMMUNICATION TECHNOLOGIES (IEEE CHILECON 2021), 2021, : 107 - 112
  • [44] Switching-Luenberger-observer-based redundant control under DoS attacks
    Lai S.-Y.
    Chen B.
    Yu L.
    Kongzhi Lilun Yu Yingyong/Control Theory and Applications, 2020, 37 (04): : 758 - 766
  • [45] Formation Control for Multiple Quadrotors Under DoS Attacks via Singular Perturbation
    Zhang, Ying
    Ma, Lei
    Yang, Chunyu
    Zhou, Linna
    Wang, Guoqing
    Dai, Wei
    IEEE TRANSACTIONS ON AEROSPACE AND ELECTRONIC SYSTEMS, 2023, 59 (04) : 4753 - 4762
  • [46] Resilient Integrated Control for AIOT Systems under DoS Attacks and Packet Loss
    Cao, Xiaoya
    Wang, Wenting
    Chen, Zhenya
    Wang, Xin
    Yang, Ming
    ELECTRONICS, 2024, 13 (09)
  • [47] Active Control Strategy for Disturbed Switched Systems Under Asynchronous DoS Attacks
    Zhao, Rui
    Zuo, Zhiqiang
    Wang, Yijing
    Zhang, Wentao
    IEEE CONTROL SYSTEMS LETTERS, 2022, 6 : 2701 - 2706
  • [48] Inherent attack tolerance properties of model predictive control under DoS attacks
    Zhang, Chenrui
    Jiang, Yiming
    Shen, Shuang
    Zeru, Rediet Tesfaye
    Xia, Yuanqing
    Chai, Senchun
    JOURNAL OF THE FRANKLIN INSTITUTE-ENGINEERING AND APPLIED MATHEMATICS, 2024, 361 (04): : 1371 - 1385
  • [49] Secured Formation Control for Multi-agent Systems Under DoS Attacks
    Amullen, Esther M.
    Shetty, Sachin
    Keel, Lee H.
    2016 IEEE SYMPOSIUM ON TECHNOLOGIES FOR HOMELAND SECURITY (HST), 2016,
  • [50] White Box Analysis at the Service of Low Rate Saturation Attacks on Virtual SDN Data Plane
    Khorsandroo, Sajad
    Tosun, Ali Saman
    2019 IEEE 44TH LOCAL COMPUTER NETWORKS (LCN) SYMPOSIUM ON EMERGING TOPICS IN NETWORKING (LCN SYMPOSIUM 2019), 2019, : 100 - 107