StateSec: Stateful Monitoring for DDoS Protection in Software Defined Networks

被引:0
|
作者
Boite, Julien [1 ]
Nardin, Pierre-Alexis [1 ]
Rebecchi, Filippo [1 ]
Bouet, Mathieu [1 ]
Conan, Vania [1 ]
机构
[1] Thales Commun & Secur, Gennevilliers, France
关键词
ANOMALY DETECTION;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Software-Defined Networking (SDN) allows for fast reactions to security threats by dynamically enforcing simple forwarding rules as counter-measures. However, in classic SDN all the intelligence resides at the controller, with the switches only capable of performing stateless forwarding as ruled by the controller. It follows that the controller, in addition to network management and control duties, must collect and process any piece of information required to take advanced (stateful) forwarding decisions. This threatens both to overload the controller and to congest the control channel. On the other hand, stateful SDN represents a new concept, developed both to improve reactivity and to offload the controller and the control channel by delegating local treatments to the switches. In this paper, we adopt this stateful paradigm to protect end-hosts from Distributed Denial of Service (DDoS). We propose StateSec, a novel approach based on in-switch processing capabilities to detect and mitigate DDoS attacks. StateSec monitors packets matching configurable traffic features (e.g., IP src/dst, port src/dst) without resorting to the controller. By feeding an entropy-based algorithm with such monitoring features, StateSec detects and mitigates several threats such as (D) DoS and port scans with high accuracy. We implemented StateSec and compared it with a state-of-the-art approach to monitor traffic in SDN. We show that StateSec is more efficient: it achieves very accurate detection levels, limiting at the same time the control plane overhead.
引用
收藏
页数:9
相关论文
共 50 条
  • [1] DDoS protection with stateful software-defined networking
    Rebecchi, Filippo
    Boite, Julien
    Nardin, Pierre-Alexis
    Bouet, Mathieu
    Conan, Vania
    [J]. INTERNATIONAL JOURNAL OF NETWORK MANAGEMENT, 2019, 29 (01)
  • [2] A survey on stateful data plane in software defined networks
    Zhang, Xiaoquan
    Cui, Lin
    Wei, Kaimin
    Tso, Fung Po
    Ji, Yangyang
    Jia, Weijia
    [J]. COMPUTER NETWORKS, 2021, 184
  • [3] Simulation of DDoS Attack on Software Defined Networks
    Bikbulatov, Timur R.
    Kurochkin, Ilya I.
    [J]. COMPUTATIONAL MECHANICS AND MODERN APPLIED SOFTWARE SYSTEMS (CMMASS'2019), 2019, 2181
  • [4] DDoS Attack in Software Defined Networks: A Survey
    XU Xiaoqiong
    YU Hongfang
    YANG Kun
    [J]. ZTE Communications, 2017, 15 (03) : 13 - 19
  • [5] Future of DDoS Attacks Mitigation in Software Defined Networks
    Vizvary, Martin
    Vykopal, Jan
    [J]. MONITORING AND SECURING VIRTUALIZED NETWORKS AND SERVICES, 2014, 8508 : 123 - 127
  • [6] DDoS flooding attack mitigation in software defined networks
    Mahrach, Safaa
    Haqiq, Abdelkrim
    [J]. International Journal of Advanced Computer Science and Applications, 2020, 11 (01): : 693 - 700
  • [7] Entropy based DDoS Detection in Software Defined Networks
    Fioravanti, Giovanni
    Spina, Mattia Giovanni
    De Rango, Floriano
    [J]. 2023 IEEE 20TH CONSUMER COMMUNICATIONS & NETWORKING CONFERENCE, CCNC, 2023,
  • [8] Mitigation and Detection of DDoS Attacks in Software Defined Networks
    Murtuza, Shariq
    Asawa, Krishna
    [J]. 2018 ELEVENTH INTERNATIONAL CONFERENCE ON CONTEMPORARY COMPUTING (IC3), 2018, : 389 - 391
  • [9] DDoS Flooding Attack Mitigation in Software Defined Networks
    Mahrach, Safaa
    Haqiq, Abdelkrim
    [J]. INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2020, 11 (01) : 693 - 700
  • [10] Multi-level Stateful Firewall Mechanism for Software Defined Networks
    Nife, Fahad
    Kotulski, Zbigniew
    [J]. COMPUTER NETWORKS (CN 2017), 2017, 718 : 271 - 286