Entropy-based DoS Attack identification in SDN

被引:21
|
作者
Carvalho, Ranyelson N. [1 ]
Bordim, Jacir L. [1 ]
Alchieri, Eduardo A. P. [1 ]
机构
[1] Univ Brasilia UnB, Dept Comp Sci, Brasilia, DF, Brazil
关键词
OPENFLOW;
D O I
10.1109/IPDPSW.2019.00108
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Software Defined Networks (SDN) represent a new network architecture that provides central control over the network. The main innovation behind an SDN network is that it decouples the data plane from the control plane, which defines a network programmable environment. In the control plane, the controller supports the execution of services that define the control policies and distributes these rules to the data plane through a standard protocol, such as OpenFlow. Despite the numerous benefits provided by this architecture, the security of an SDN network is still a matter of concern since the aforementioned decoupling increase the attack surface in the network. In fact, Denial of Service (DoS) attacks are the ones that challenge the SDN environments in many aspects, mainly due to vulnerabilities between the control and the data plane layers. Entropy-based DoS detection method is a technique widely used in conventional network architecture. This paper proposes the use of entropy in an SDN environment, through of the OpenFlow switches statistics, to build a mechanism that monitor the network and is able to differentiate DoS traffic from the benign traffic. Experimental results show the practical feasibility of the proposed solution.
引用
收藏
页码:627 / 634
页数:8
相关论文
共 50 条
  • [21] IP packet size entropy-based scheme for detection of DoS/DDoS attacks
    Du, Ping
    Abe, Shunji
    IEICE TRANSACTIONS ON INFORMATION AND SYSTEMS, 2008, E91D (05) : 1274 - 1281
  • [22] A Cross Entropy-Based Approach to Controller Placement Problem with Link Failures in SDN
    Yin, Hanmin
    Chen, Jue
    JOURNAL OF CIRCUITS SYSTEMS AND COMPUTERS, 2023, 32 (14)
  • [23] SDN Attack Identification Model Based on CNN Algorithm
    Xue, Huimin
    Jing, Bing
    IEEE ACCESS, 2023, 11 : 87652 - 87666
  • [24] An Entropy-based DDoS attack Detection and Classification with Hierarchical Temporal Memory
    Nguyen, Manh Hung
    Yu-Kuen Lai
    Kai-Po Chang
    2021 ASIA-PACIFIC SIGNAL AND INFORMATION PROCESSING ASSOCIATION ANNUAL SUMMIT AND CONFERENCE (APSIPA ASC), 2021, : 1942 - 1948
  • [25] Entropy-based moment selection in the presence of weak identification
    Hall, Alastair R.
    Inoue, Atsushi
    Shin, Changmock
    ECONOMETRIC REVIEWS, 2008, 27 (4-6) : 398 - 427
  • [26] Identification of flood seasonality using an entropy-based method
    Xiong, Feng
    Guo, Shenglian
    Chen, Lu
    Chang, Fi-John
    Zhong, Yixuan
    Liu, Pan
    STOCHASTIC ENVIRONMENTAL RESEARCH AND RISK ASSESSMENT, 2018, 32 (11) : 3021 - 3035
  • [27] Identification of flood seasonality using an entropy-based method
    Feng Xiong
    Shenglian Guo
    Lu Chen
    Fi-John Chang
    Yixuan Zhong
    Pan Liu
    Stochastic Environmental Research and Risk Assessment, 2018, 32 : 3021 - 3035
  • [28] DDoS Attack Detection Model Based on Information Entropy and DNN in SDN
    Zhang L.
    Wang J.
    Jisuanji Yanjiu yu Fazhan/Computer Research and Development, 2019, 56 (05): : 909 - 918
  • [29] An Online Entropy-Based DDoS Flooding Attack Detection System With Dynamic Threshold
    Tsobdjou, Loic D.
    Pierre, Samuel
    Quintero, Alejandro
    IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2022, 19 (02): : 1679 - 1689
  • [30] Entropy-based denial-of-service attack detection in cloud data center
    Cao, Jiuxin
    Yu, Bin
    Dong, Fang
    Zhu, Xiangying
    Xu, Shuai
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2015, 27 (18): : 5623 - 5639