Towards Crossfire Distributed Denial of Service Attack Protection Using Intent-Based Moving Target Defense Over Software-Defined Networking

被引:10
|
作者
Hyder, Muhammad Faraz [1 ]
Fatima, Tasbiha [2 ]
机构
[1] NED Univ Engn & Technol, Dept Software Engn & Technol, Karachi 75270, Pakistan
[2] NED Univ Engn & Technol, Dept Comp Sci & Informat Technol, Karachi 75270, Pakistan
关键词
Denial-of-service attack; Computer crime; Security; Software; Ports (computers); Hardware; Cloud computing; Crossfire DDoS; network function virtualization; intent-based networking; moving target defense; software defined networking; SDN;
D O I
10.1109/ACCESS.2021.3103845
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Crossfire is an indirect target area link-flooding Distributed Denial of Service (DDoS) attack determined to affect the neighbors of the real target. Currently, Crossfire DDoS attacks are acquiring impetus because of their indistinguishability and undetectability. SDN (Software Defined Networking) is a progressing technique because of its adaptability and programmability. Moving Target Defense (MTD) is an arising security strategy to counter attacks by progressively changing the attacked plane. IBN (Intent-based Networking) is another promising methodology for providing dynamic network management. IBN-based MTD can provide efficient MTD solutions because of the concentrated control and observing capacities of the intents when translated into rules inside the SDN control plane. In this paper, a framework for the security of Crossfire DDoS attacks is proposed by making use of Intent-based Traffic modifications through the Open Networking Operating System (ONOS) Rest API and Domain Name System (DNS) port redirection. In this paper, we exploited Intent-based MTD to divert traffic from the principal host to virtual shadow hosts to counter this attack. Traffic redirection helps in masquerading the attacker headed for shadow host and consequently getting the erroneous path towards the network and, hence, the Crossfire attack couldn't be executed as expected. The proposed technique is simulated using Mininet and ONOS SDN controllers. The outcomes showed traffic is successfully redirected at a low computational expense. Therefore, Crossfire DDoS is efficiently mitigated as promising results are found.
引用
收藏
页码:112792 / 112804
页数:13
相关论文
共 50 条
  • [21] Mitigation of Denial of Service Attacks Using OpenDaylight Application in Software-Defined Networking
    Cajas, Carlos D.
    Budanov, Dmitry O.
    PROCEEDINGS OF THE 2021 IEEE CONFERENCE OF RUSSIAN YOUNG RESEARCHERS IN ELECTRICAL AND ELECTRONIC ENGINEERING (ELCONRUS), 2021, : 260 - 265
  • [22] Distributed Denial of Service Defense in Software Defined Network Using OpenFlow
    Zhai, Pengfei
    Song, Yanbo
    Zhu, Xiaoming
    Cao, Lihui
    Zhang, Jiaming
    Yang, Chungang
    2020 IEEE/CIC INTERNATIONAL CONFERENCE ON COMMUNICATIONS IN CHINA (ICCC), 2020, : 1274 - 1279
  • [23] Performability Analysis of Services in a Software-Defined Networking Adopting Time-Based Moving Target Defense
    Mendonca, Julio
    Cho, Jin-Hee
    Moore, Terrence J.
    Nelson, Frederica F.
    Lim, Hyuk
    Zimmermann, Armin
    Kim, Dong Seong
    PROCEEDINGS OF THE 35TH ANNUAL ACM SYMPOSIUM ON APPLIED COMPUTING (SAC'20), 2020, : 1180 - 1189
  • [24] Towards adding digital forensics capabilities in software defined networking based moving target defense
    Hyder, Muhammad Faraz
    Fatima, Tasbiha
    Arshad, Saadia
    CLUSTER COMPUTING-THE JOURNAL OF NETWORKS SOFTWARE TOOLS AND APPLICATIONS, 2024, 27 (01): : 893 - 912
  • [25] Towards adding digital forensics capabilities in software defined networking based moving target defense
    Muhammad Faraz Hyder
    Tasbiha Fatima
    Saadia Arshad
    Cluster Computing, 2024, 27 : 893 - 912
  • [26] Random Host and Service Multiplexing for Moving Target Defense in Software-Defined Networks
    Sharma, Dilli P.
    Cho, Jin-Hee
    Moore, Terrence J.
    Nelson, Frederica F.
    Lim, Hyuk
    Kim, Dong Seong
    ICC 2019 - 2019 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2019,
  • [27] Detection Techniques of Distributed Denial of Service Attacks on Software-Defined Networking Controller-A Review
    Aladaileh, Mohammad A.
    Anbar, Mohammed
    Hasbullah, Iznan H.
    Chong, Yung-Wey
    Sanjalawe, Yousef K.
    IEEE ACCESS, 2020, 8 : 143985 - 143995
  • [28] A Novel Distributed Denial-of-Service Attack Detection Scheme for Software Defined Networking Environments
    Wu, Di
    Li, Jie
    Das, Sajal K.
    Wu, Jinsong
    Ji, Yusheng
    Li, Zhetao
    2018 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2018,
  • [29] Traffic-aware service relocation in software-defined and intent-based elastic optical networks
    Goscien, Reza
    COMPUTER NETWORKS, 2023, 225
  • [30] Traffic Feature Selection and Distributed Denial of Service Attack Detection in Software-Defined Networks Based on Machine Learning
    Han, Daoqi
    Li, Honghui
    Fu, Xueliang
    Zhou, Shuncheng
    SENSORS, 2024, 24 (13)