Towards Crossfire Distributed Denial of Service Attack Protection Using Intent-Based Moving Target Defense Over Software-Defined Networking

被引:10
|
作者
Hyder, Muhammad Faraz [1 ]
Fatima, Tasbiha [2 ]
机构
[1] NED Univ Engn & Technol, Dept Software Engn & Technol, Karachi 75270, Pakistan
[2] NED Univ Engn & Technol, Dept Comp Sci & Informat Technol, Karachi 75270, Pakistan
关键词
Denial-of-service attack; Computer crime; Security; Software; Ports (computers); Hardware; Cloud computing; Crossfire DDoS; network function virtualization; intent-based networking; moving target defense; software defined networking; SDN;
D O I
10.1109/ACCESS.2021.3103845
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Crossfire is an indirect target area link-flooding Distributed Denial of Service (DDoS) attack determined to affect the neighbors of the real target. Currently, Crossfire DDoS attacks are acquiring impetus because of their indistinguishability and undetectability. SDN (Software Defined Networking) is a progressing technique because of its adaptability and programmability. Moving Target Defense (MTD) is an arising security strategy to counter attacks by progressively changing the attacked plane. IBN (Intent-based Networking) is another promising methodology for providing dynamic network management. IBN-based MTD can provide efficient MTD solutions because of the concentrated control and observing capacities of the intents when translated into rules inside the SDN control plane. In this paper, a framework for the security of Crossfire DDoS attacks is proposed by making use of Intent-based Traffic modifications through the Open Networking Operating System (ONOS) Rest API and Domain Name System (DNS) port redirection. In this paper, we exploited Intent-based MTD to divert traffic from the principal host to virtual shadow hosts to counter this attack. Traffic redirection helps in masquerading the attacker headed for shadow host and consequently getting the erroneous path towards the network and, hence, the Crossfire attack couldn't be executed as expected. The proposed technique is simulated using Mininet and ONOS SDN controllers. The outcomes showed traffic is successfully redirected at a low computational expense. Therefore, Crossfire DDoS is efficiently mitigated as promising results are found.
引用
收藏
页码:112792 / 112804
页数:13
相关论文
共 50 条
  • [1] A Defense Mechanism for Distributed Denial of Service Attack in Software-Defined Networks
    Luo, Shibo
    Wu, Jun
    Li, Jianhua
    Pei, Bei
    2015 NINTH INTERNATIONAL CONFERENCE ON FRONTIER OF COMPUTER SCIENCE AND TECHNOLOGY FCST 2015, 2015, : 324 - 328
  • [2] INMTD: Intent-based Moving Target Defense Framework using Software Defined Networks
    Hyder, Muhammad Faraz
    Ismail, Muhammad Ali
    ENGINEERING TECHNOLOGY & APPLIED SCIENCE RESEARCH, 2020, 10 (01) : 5142 - 5147
  • [3] Digital forensics framework for intent-based networking over software-defined networks
    Muhammad Faraz Hyder
    Tasbiha Fatima
    Saadia Arshad
    Telecommunication Systems, 2024, 85 : 11 - 27
  • [4] Digital forensics framework for intent-based networking over software-defined networks
    Hyder, Muhammad Faraz
    Fatima, Tasbiha
    Arshad, Saadia
    TELECOMMUNICATION SYSTEMS, 2024, 85 (01) : 11 - 27
  • [5] Amplified Distributed Denial of Service Attack in Software Defined Networking
    Ambrosin, Moreno
    Conti, Mauro
    De Gaspari, Fabio
    Devarajan, Nishanth
    2016 8TH IFIP INTERNATIONAL CONFERENCE ON NEW TECHNOLOGIES, MOBILITY AND SECURITY (NTMS), 2016,
  • [6] Distributed Denial of Service Classification for Software-Defined Networking Using Grammatical Evolution
    Spyrou, Evangelos D.
    Tsoulos, Ioannis
    Stylios, Chrysostomos
    Davoli, Franco
    FUTURE INTERNET, 2023, 15 (12)
  • [7] A novel Distributed Denial of Service attack defense scheme for Software-Defined Networking using Packet-In message and frequency domain analysis
    Fouladi, Ramin Fadaei
    Karaçay, Leyli
    Gülen, Utku
    Soykan, Elif Ustundag
    Computers and Electrical Engineering, 2024, 120
  • [8] Towards Dynamically Shifting Cyber Terrain With Software-Defined Networking and Moving Target Defense
    Larkin, Robert
    Jensen, Steven
    Koranek, Daniel
    Mullins, Barry
    Reith, Mark
    PROCEEDINGS OF THE 16TH INTERNATIONAL CONFERENCE ON CYBER WARFARE AND SECURITY (ICCWS 2021), 2021, : 535 - 540
  • [9] Frequency-Minimal Moving Target Defense using Software-Defined Networking
    Debroy, Saptarshi
    Calyam, Prasad
    Nguyen, Minh
    Stage, Allen
    Georgiev, Vladimir
    2016 INTERNATIONAL CONFERENCE ON COMPUTING, NETWORKING AND COMMUNICATIONS (ICNC), 2016,
  • [10] Distributed Denial of Service Attacks in Software-Defined Networking with Cloud Computing
    Yan, Qiao
    Yu, F. Richard
    IEEE COMMUNICATIONS MAGAZINE, 2015, 53 (04) : 52 - 59