Early Detection of DDoS Attacks against SDN Controllers

被引:0
|
作者
Mousavi, Seyed Mohammad [1 ]
St-Hilaire, Marc [1 ]
机构
[1] Carleton Univ, Dept Syst & Comp Engn, Ottawa, ON, Canada
关键词
DDoS attack; SDN; Controller; Entropy;
D O I
暂无
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
A Software Defined Network (SDN) is a new network architecture that provides central control over the network. Although central control is the major advantage of SDN, it is also a single point of failure if it is made unreachable by a Distributed Denial of Service (DDoS) Attack. To mitigate this threat, this paper proposes to use the central control of SDN for attack detection and introduces a solution that is effective and lightweight in terms of the resources that it uses. More precisely, this paper shows how DDoS attacks can exhaust controller resources and provides a solution to detect such attacks based on the entropy variation of the destination IP address. This method is able to detect DDoS within the first five hundred packets of the attack traffic.
引用
收藏
页码:77 / 81
页数:5
相关论文
共 50 条
  • [1] A protocol for cluster confirmations of SDN controllers against DDoS attacks
    Iranmanesh, Amir
    Naji, Hamid Reza
    [J]. COMPUTERS & ELECTRICAL ENGINEERING, 2021, 93
  • [2] Early Detection of DDoS Attacks Against Software Defined Network Controllers
    Mousavi, Seyed Mohammad
    St-Hilaire, Marc
    [J]. JOURNAL OF NETWORK AND SYSTEMS MANAGEMENT, 2018, 26 (03) : 573 - 591
  • [3] Early Detection of DDoS Attacks Against Software Defined Network Controllers
    Seyed Mohammad Mousavi
    Marc St-Hilaire
    [J]. Journal of Network and Systems Management, 2018, 26 : 573 - 591
  • [4] Detection of DDoS Attacks Against Wireless SDN Controllers Based on the Fuzzy Synthetic Evaluation Decision-making Model
    Yan, Qiao
    Gong, Qingxiang
    Deng, Fang-an
    [J]. AD HOC & SENSOR WIRELESS NETWORKS, 2016, 33 (1-4) : 275 - 299
  • [5] A Statistical Model for Early Detection of DDoS Attacks on Random Targets in SDN
    Shohani, Reza Bakhtiari
    Mostafavi, Seyedakbar
    Hakami, Vesal
    [J]. WIRELESS PERSONAL COMMUNICATIONS, 2021, 120 (01) : 379 - 400
  • [6] An integrated SDN framework for early detection of DDoS attacks in cloud computing
    Songa, Asha Varma
    Karri, Ganesh Reddy
    [J]. JOURNAL OF CLOUD COMPUTING-ADVANCES SYSTEMS AND APPLICATIONS, 2024, 13 (01):
  • [7] An integrated SDN framework for early detection of DDoS attacks in cloud computing
    Asha Varma Songa
    Ganesh Reddy Karri
    [J]. Journal of Cloud Computing, 13
  • [8] A Statistical Model for Early Detection of DDoS Attacks on Random Targets in SDN
    Reza Bakhtiari Shohani
    Seyedakbar Mostafavi
    Vesal Hakami
    [J]. Wireless Personal Communications, 2021, 120 : 379 - 400
  • [9] SDN-Based Intrusion Detection System for Early Detection and Mitigation of DDoS Attacks
    Manso, Pedro
    Moura, Jose
    Serrao, Carlos
    [J]. INFORMATION, 2019, 10 (03)
  • [10] An RBF-PSO Based Approach for Early Detection of DDoS Attacks in SDN
    Dayal, Neelam
    Srivastava, Shashank
    [J]. 2018 10TH INTERNATIONAL CONFERENCE ON COMMUNICATION SYSTEMS & NETWORKS (COMSNETS), 2018, : 17 - 24