Towards Crossfire Distributed Denial of Service Attack Protection Using Intent-Based Moving Target Defense Over Software-Defined Networking

被引:10
|
作者
Hyder, Muhammad Faraz [1 ]
Fatima, Tasbiha [2 ]
机构
[1] NED Univ Engn & Technol, Dept Software Engn & Technol, Karachi 75270, Pakistan
[2] NED Univ Engn & Technol, Dept Comp Sci & Informat Technol, Karachi 75270, Pakistan
关键词
Denial-of-service attack; Computer crime; Security; Software; Ports (computers); Hardware; Cloud computing; Crossfire DDoS; network function virtualization; intent-based networking; moving target defense; software defined networking; SDN;
D O I
10.1109/ACCESS.2021.3103845
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Crossfire is an indirect target area link-flooding Distributed Denial of Service (DDoS) attack determined to affect the neighbors of the real target. Currently, Crossfire DDoS attacks are acquiring impetus because of their indistinguishability and undetectability. SDN (Software Defined Networking) is a progressing technique because of its adaptability and programmability. Moving Target Defense (MTD) is an arising security strategy to counter attacks by progressively changing the attacked plane. IBN (Intent-based Networking) is another promising methodology for providing dynamic network management. IBN-based MTD can provide efficient MTD solutions because of the concentrated control and observing capacities of the intents when translated into rules inside the SDN control plane. In this paper, a framework for the security of Crossfire DDoS attacks is proposed by making use of Intent-based Traffic modifications through the Open Networking Operating System (ONOS) Rest API and Domain Name System (DNS) port redirection. In this paper, we exploited Intent-based MTD to divert traffic from the principal host to virtual shadow hosts to counter this attack. Traffic redirection helps in masquerading the attacker headed for shadow host and consequently getting the erroneous path towards the network and, hence, the Crossfire attack couldn't be executed as expected. The proposed technique is simulated using Mininet and ONOS SDN controllers. The outcomes showed traffic is successfully redirected at a low computational expense. Therefore, Crossfire DDoS is efficiently mitigated as promising results are found.
引用
收藏
页码:112792 / 112804
页数:13
相关论文
共 50 条
  • [31] POSTER: Toward Intelligent Cyber Attacks for Moving Target Defense Techniques in Software-Defined Networking
    Moghaddam, Tina
    Yang, Guowei
    Thapa, Chandra
    Camtepe, Seyit
    Kim, Dan Dongseong
    PROCEEDINGS OF THE 2023 ACM ASIA CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, ASIA CCS 2023, 2023, : 1022 - 1024
  • [32] Towards Enhancing the Endpoint Security using Moving Target Defense (Shuffle-based Approach) in Software Defined Networking
    Hyder, Muhammad Faraz
    Waseemullah
    Farooq, Muhammad Umer
    Ahmed, Usama
    Raza, Wajahat
    ENGINEERING TECHNOLOGY & APPLIED SCIENCE RESEARCH, 2021, 11 (04) : 7483 - 7488
  • [33] Intent-based zero-touch service chaining layer for software-defined edge cloud networks
    Martini, B.
    Gharbaoui, M.
    Castoldi, P.
    COMPUTER NETWORKS, 2022, 212
  • [34] Intent-based zero-touch service chaining layer for software-defined edge cloud networks
    Martini, B.
    Gharbaoui, M.
    Castoldi, P.
    Computer Networks, 2022, 212
  • [35] Statistical Approach Based Detection of Distributed Denial of Service Attack in a Software Defined Network
    Bavani, K.
    Ramkumar, M. P.
    Selvan, Emil G. S. R.
    2020 6TH INTERNATIONAL CONFERENCE ON ADVANCED COMPUTING AND COMMUNICATION SYSTEMS (ICACCS), 2020, : 380 - 385
  • [36] Distributed Denial of Service Attack Detection Based on Object Character in Software Defined Network
    Yao Linyuan
    Dong Ping
    Zhang Hongke
    JOURNAL OF ELECTRONICS & INFORMATION TECHNOLOGY, 2017, 39 (02) : 381 - 388
  • [37] A Novel Approach for distributed denial of service defense using continuous wavelet transform and convolutional neural network for software-Defined network
    Fouladi, Ramin Fadaei
    Ermiş, Orhan
    Anarim, Emin
    Computers and Security, 2022, 112
  • [38] A Novel Approach for distributed denial of service defense using continuous wavelet transform and convolutional neural network for software-Defined network
    Fouladi, Ramin Fadaei
    Ermis, Orhan
    Anarim, Emin
    COMPUTERS & SECURITY, 2022, 112
  • [39] Dynamic Security Metrics for Software-Defined Network-based Moving Target Defense
    Sharma, Dilli P.
    Enoch, Simon Yusuf
    Cho, Jin-Hee
    Moore, Terrence J.
    Nelson, Frederica F.
    Lim, Hyuk
    Kim, Dong Seong
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2020, 170
  • [40] Poster: Address Shuffling based Moving Target Defense for In-Vehicle Software-Defined Networks
    Yoon, Seunghyun
    Cho, Jin-Hee
    Kim, Dong Seong
    Moore, Terrence J.
    Nelson, Frederica
    Lim, Hyuk
    MOBICOM'19: PROCEEDINGS OF THE 25TH ANNUAL INTERNATIONAL CONFERENCE ON MOBILE COMPUTING AND NETWORKING, 2019,