Entropy-based DoS Attack identification in SDN

被引:21
|
作者
Carvalho, Ranyelson N. [1 ]
Bordim, Jacir L. [1 ]
Alchieri, Eduardo A. P. [1 ]
机构
[1] Univ Brasilia UnB, Dept Comp Sci, Brasilia, DF, Brazil
关键词
OPENFLOW;
D O I
10.1109/IPDPSW.2019.00108
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Software Defined Networks (SDN) represent a new network architecture that provides central control over the network. The main innovation behind an SDN network is that it decouples the data plane from the control plane, which defines a network programmable environment. In the control plane, the controller supports the execution of services that define the control policies and distributes these rules to the data plane through a standard protocol, such as OpenFlow. Despite the numerous benefits provided by this architecture, the security of an SDN network is still a matter of concern since the aforementioned decoupling increase the attack surface in the network. In fact, Denial of Service (DoS) attacks are the ones that challenge the SDN environments in many aspects, mainly due to vulnerabilities between the control and the data plane layers. Entropy-based DoS detection method is a technique widely used in conventional network architecture. This paper proposes the use of entropy in an SDN environment, through of the OpenFlow switches statistics, to build a mechanism that monitor the network and is able to differentiate DoS traffic from the benign traffic. Experimental results show the practical feasibility of the proposed solution.
引用
收藏
页码:627 / 634
页数:8
相关论文
共 50 条
  • [31] Entropy-based template analysis in face biometric identification systems
    Maria De Marsico
    Michele Nappi
    Daniel Riccio
    Genoveffa Tortora
    Signal, Image and Video Processing, 2013, 7 : 493 - 505
  • [32] Minimizing false positive rate for DoS attack detection: A hybrid SDN-based approach
    Latah, Majd
    Toker, Levent
    ICT EXPRESS, 2020, 6 (02): : 125 - 127
  • [33] Sensational Headline Identification By Normalized Cross Entropy-Based Metric
    Yang, Zhen
    Gao, Kaiming
    Fan, Kefeng
    Lai, Yingxu
    COMPUTER JOURNAL, 2015, 58 (04): : 644 - 655
  • [34] Entropy-based template analysis in face biometric identification systems
    De Marsico, Maria
    Nappi, Michele
    Riccio, Daniel
    Tortora, Genoveffa
    SIGNAL IMAGE AND VIDEO PROCESSING, 2013, 7 (03) : 493 - 505
  • [35] A cooperative DDoS attack detection scheme based on entropy and ensemble learning in SDN
    Shanshan Yu
    Jicheng Zhang
    Ju Liu
    Xiaoqing Zhang
    Yafeng Li
    Tianfeng Xu
    EURASIP Journal on Wireless Communications and Networking, 2021
  • [36] A DDoS Attack Detection Method Based on Information Entropy and Deep Learning in SDN
    Wang, Lu
    Liu, Ying
    PROCEEDINGS OF 2020 IEEE 4TH INFORMATION TECHNOLOGY, NETWORKING, ELECTRONIC AND AUTOMATION CONTROL CONFERENCE (ITNEC 2020), 2020, : 1084 - 1088
  • [37] A cooperative DDoS attack detection scheme based on entropy and ensemble learning in SDN
    Yu, Shanshan
    Zhang, Jicheng
    Liu, Ju
    Zhang, Xiaoqing
    Li, Yafeng
    Xu, Tianfeng
    EURASIP JOURNAL ON WIRELESS COMMUNICATIONS AND NETWORKING, 2021, 2021 (01)
  • [38] A DDoS Attack Detection Method Using Conditional Entropy Based on SDN Traffic
    Tian, Qiwen
    Miyata, Sumiko
    IOT, 2023, 4 (02): : 95 - 111
  • [39] DTGuard: A Lightweight Defence Mechanism Against a New DoS Attack on SDN
    Hou, Jianwei
    Zhang, Ziqi
    Shi, Wenchang
    Qin, Bo
    Bin, Liang
    INFORMATION AND COMMUNICATIONS SECURITY (ICICS 2019), 2020, 11999 : 503 - 520
  • [40] Reduction of traffic between switches and IDS for prevention of DoS attack in SDN
    Quingueni, Andre Mbundo
    Kitsuwan, Nattapong
    ISCIT 2019: PROCEEDINGS OF 2019 19TH INTERNATIONAL SYMPOSIUM ON COMMUNICATIONS AND INFORMATION TECHNOLOGIES (ISCIT), 2019, : 277 - 281