DDoS attack protection in the era of cloud computing and Software-Defined Networking

被引:234
|
作者
Wang, Bing [1 ]
Zheng, Yao [1 ]
Lou, Wenjing [1 ]
Hou, Y. Thomas [1 ]
机构
[1] Virginia Polytech Inst & State Univ, Blacksburg, VA 24061 USA
基金
美国国家科学基金会;
关键词
DDoS mitigation; Software-Defined Networking; Graphical model;
D O I
10.1016/j.comnet.2015.02.026
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Cloud computing has become the real trend of enterprise IT service model that offers cost-effective and scalable processing. Meanwhile, Software-Defined Networking (SON) is gaining popularity in enterprise networks for flexibility in network management service and reduced operational cost. There seems a trend for the two technologies to go hand-in-hand in providing an enterprise's IT services. However, the new challenges brought by the marriage of cloud computing and SDN, particularly the implications on enterprise network security, have not been well understood. This paper sets to address this important problem. We start by examining the security impact, in particular, the impact on DDoS attack defense mechanisms, in an enterprise network where both technologies are adopted. We find that SDN technology can actually help enterprises to defend against DDoS attacks if the defense architecture is designed properly. To that end, we propose a DDoS attack mitigation architecture that integrates a highly programmable network monitoring to enable attack detection and a flexible control structure to allow fast and specific attack reaction. To cope with the new architecture, we propose a graphic model based attack detection system that can deal with the dataset shift problem. The simulation results show that our architecture can effectively and efficiently address the security challenges brought by the new network paradigm and our attack detection system can effectively report various attacks using real-world network traffic. (C) 2015 Elsevier B.V. All rights reserved.
引用
收藏
页码:308 / 319
页数:12
相关论文
共 50 条
  • [1] DDoS Attack Protection in the Era of Cloud Computing and Software-Defined Networking
    Wang, Bing
    Zheng, Yao
    Lou, Wenjing
    Hou, Y. Thomas
    [J]. 2014 IEEE 22ND INTERNATIONAL CONFERENCE ON NETWORK PROTOCOLS (ICNP), 2014, : 624 - 629
  • [2] DDoS protection with stateful software-defined networking
    Rebecchi, Filippo
    Boite, Julien
    Nardin, Pierre-Alexis
    Bouet, Mathieu
    Conan, Vania
    [J]. INTERNATIONAL JOURNAL OF NETWORK MANAGEMENT, 2019, 29 (01)
  • [3] HTTP DDoS flooding attack mitigation in software-defined networking
    Park, Sungho
    Kim, Youngjun
    Choi, Hyungoo
    Kyung, Yeunwoong
    Park, Jinwoo
    [J]. IEICE Transactions on Information and Systems, 2021, E104D (09) : 1496 - 1499
  • [4] HTTP DDoS Flooding Attack Mitigation in Software-Defined Networking
    Park, Sungho
    Kim, Youngjun
    Choi, Hyungoo
    Kyung, Yeunwoong
    Park, Jinwoo
    [J]. IEICE TRANSACTIONS ON INFORMATION AND SYSTEMS, 2021, E104D (09): : 1496 - 1499
  • [5] FADM: DDoS Flooding Attack Detection and Mitigation System in Software-Defined Networking
    Hu, Dingwen
    Hong, Peilin
    Chen, Yixin
    [J]. GLOBECOM 2017 - 2017 IEEE GLOBAL COMMUNICATIONS CONFERENCE, 2017,
  • [6] Detection and Analysis of TCP-SYN DDoS Attack in Software-Defined Networking
    Swami, Rochak
    Dave, Mayank
    Ranga, Virender
    [J]. WIRELESS PERSONAL COMMUNICATIONS, 2021, 118 (04) : 2295 - 2317
  • [7] Detection and Analysis of TCP-SYN DDoS Attack in Software-Defined Networking
    Rochak Swami
    Mayank Dave
    Virender Ranga
    [J]. Wireless Personal Communications, 2021, 118 : 2295 - 2317
  • [8] A Taxonomy of Software-Defined Networking (SDN)-Enabled Cloud Computing
    Son, Jungmin
    Buyya, Rajkumar
    [J]. ACM COMPUTING SURVEYS, 2018, 51 (03)
  • [9] A REVIEW ON SOFTWARE-DEFINED NETWORKING ENABLED IOT CLOUD COMPUTING
    Badotra, Sumit
    Panda, Surya Narayan
    [J]. IIUM ENGINEERING JOURNAL, 2019, 20 (02): : 105 - 126
  • [10] Addressing Spoofed DDoS Attacks in Software-defined Networking
    Swami, Rochak
    Dave, Mayank
    Ranga, Virender
    [J]. 2021 6TH INTERNATIONAL CONFERENCE FOR CONVERGENCE IN TECHNOLOGY (I2CT), 2021,