ArOMA: An SDN based, autonomic DDoS mitigation framework

被引:44
|
作者
Sahay, Rishikesh [1 ,2 ]
Blanc, Gregory [1 ,2 ]
Zhang, Zonghua [2 ,3 ]
Debar, Herue [1 ,2 ]
机构
[1] Inst Mines Telecom, Telecom SudParis, Paris, France
[2] CNRS, UMR 5157, SAMOVAR, Paris, France
[3] Inst Mines Telecom, IMT Lille Douai, Lille, France
关键词
DDoS attacks; DDoS mitigation; Software Defined Networking; Anomaly detection; Security policy; MECHANISM;
D O I
10.1016/j.cose.2017.07.008
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Distributed Denial of Service (DDoS) attacks have been the plague of the Internet for more than two decades, despite the tremendous and continuous efforts from both academia and industry to counter them. The lessons learned from the past DDoS mitigation designs indicate that the heavy reliance on additional software modules and dedicated hardware devices seriously impede their widespread deployment. This paper proposes an autonomic DDoS defense framework, called ArOMA, that leverages the programmability and centralized manageability features of Software Defined Networking (SDN) paradigm. Specifically, ArOMA can systematically bridge the gaps between different security functions, ranging from traffic monitoring to anomaly, detection to mitigation, while sparing human operators from non-trivial interventions. It also facilitates the collaborations between ISPs and their customers on DDoS mitigation by logically distributing the essential security functions, allowing the ISP to handle DDoS traffic based on the requests of its customers. Our experimental results demonstrate that, in the face of DDoS flooding attacks, ArOMA can effectively maintain the performance of video streams at a satisfactory level. (C) 2017 Elsevier Ltd. All rights reserved.
引用
收藏
页码:482 / 499
页数:18
相关论文
共 50 条
  • [1] A DDoS Detection and Mitigation System Framework Based on Spark and SDN
    Yan, Qiao
    Huang, Wenyao
    [J]. SMART COMPUTING AND COMMUNICATION, SMARTCOM 2016, 2017, 10135 : 350 - 358
  • [2] Physical Assessment of an SDN-Based Security Framework for DDoS Attack Mitigation: Introducing the SDN-SlowRate-DDoS Dataset
    Yungaicela-Naula, Noe M.
    Vargas-Rosales, Cesar
    Perez-Diaz, Jesus Arturo
    Jacob, Eduardo
    Martinez-Cagnazzo, Carlos
    [J]. IEEE ACCESS, 2023, 11 : 46820 - 46831
  • [3] Detection and mitigation of DDoS in SDN
    Pande, Bhavika
    Bhagat, Gargi
    Priya, Shanu
    Agrawal, Himanshu
    [J]. 2018 ELEVENTH INTERNATIONAL CONFERENCE ON CONTEMPORARY COMPUTING (IC3), 2018, : 371 - 373
  • [4] A Machine Learning Based Detection and Mitigation of the DDOS Attack by Using SDN Controller Framework
    M. Revathi
    V. V. Ramalingam
    B. Amutha
    [J]. Wireless Personal Communications, 2022, 127 (3) : 2417 - 2441
  • [5] A Machine Learning Based Detection and Mitigation of the DDOS Attack by Using SDN Controller Framework
    Revathi, M.
    Ramalingam, V. V.
    Amutha, B.
    [J]. WIRELESS PERSONAL COMMUNICATIONS, 2022, 127 (03) : 2417 - 2441
  • [6] SDN Based Collaborative Scheme for Mitigation of DDoS Attacks
    Hameed, Sufian
    Khan, Hassan Ahmed
    [J]. FUTURE INTERNET, 2018, 10 (03)
  • [7] CyberShip: An SDN-Based Autonomic Attack Mitigation Framework for Ship Systems
    Sahay, Rishikesh
    Sepulveda, D. A.
    Meng, Weizhi
    Jensen, Christian Damsgaard
    Barfod, Michael Bruhn
    [J]. SCIENCE OF CYBER SECURITY, SCISEC 2018, 2018, 11287 : 191 - 198
  • [8] A flexible SDN-based framework for slow-rate DDoS attack mitigation by reinforcement
    Yungaicela-Naula, Noe M.
    Vargas-Rosales, Cesar
    Perez-Diaz, Jesus Arturo
    Carrera, Diego Fernando
    [J]. JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2022, 205
  • [9] Leveraging SDN for Collaborative DDoS Mitigation
    Hameed, Sufian
    Khan, Hassan Ahmed
    [J]. 2017 INTERNATIONAL CONFERENCE ON NETWORKED SYSTEMS (NETSYS), 2017,
  • [10] Prevention and Mitigation of DNS based DDoS attacks in SDN Environment
    Saharan, Shail
    Gupta, Vishal
    [J]. 2019 11TH INTERNATIONAL CONFERENCE ON COMMUNICATION SYSTEMS & NETWORKS (COMSNETS), 2019, : 606 - 608