DDoS protection with stateful software-defined networking

被引:16
|
作者
Rebecchi, Filippo [1 ]
Boite, Julien [1 ]
Nardin, Pierre-Alexis [1 ]
Bouet, Mathieu [1 ]
Conan, Vania [1 ]
机构
[1] Thales Commun & Secur, Adv Informat Technol Lab, Gennevilliers, France
基金
欧盟地平线“2020”;
关键词
DEFENSE-MECHANISMS; ANOMALY DETECTION; ATTACKS;
D O I
10.1002/nem.2042
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Distributed denial of service (DDoS) attacks represent one of the most critical security challenges facing network operators. Software-defined networking (SDN) permits fast reactions to such threats by dynamically enforcing simple forwarding/blocking rules as countermeasures. However, the centralization of the control plane requires that the SDN controller, besides network management operations, should also collect information to identify and mitigate the security menaces. A major drawback of this approach is that it may overload the controller and the control channel. On the other hand, stateful SDN represents a new concept, developed to improve reactivity and offload the controller by delegating local treatments to the switches. In this article, we embrace this paradigm to protect end-hosts from DDoS attacks. We propose StateSec, a novel approach based on in-switch processing capabilities to detect and mitigate flooding threats. StateSec monitors packets matching configurable traffic features without resorting to the controller. By feeding an entropy-based detection algorithm with such monitoring features, it detects and mitigates several threats such as (D)DoS with high accuracy. We implemented StateSec in an SDN platform comparing it with state-of-the-art approaches. We show that StateSec is far more efficient: It achieves very accurate detection levels, reducing at the same time the control plane overhead. We have also evaluated the memory footprint of StateSec for a possible use in production. Finally, we deployed StateSec over a real network to tune its parameters and assess its suitability to real-world deployments.
引用
收藏
页数:19
相关论文
共 50 条
  • [1] DDoS attack protection in the era of cloud computing and Software-Defined Networking
    Wang, Bing
    Zheng, Yao
    Lou, Wenjing
    Hou, Y. Thomas
    [J]. COMPUTER NETWORKS, 2015, 81 : 308 - 319
  • [2] DDoS Attack Protection in the Era of Cloud Computing and Software-Defined Networking
    Wang, Bing
    Zheng, Yao
    Lou, Wenjing
    Hou, Y. Thomas
    [J]. 2014 IEEE 22ND INTERNATIONAL CONFERENCE ON NETWORK PROTOCOLS (ICNP), 2014, : 624 - 629
  • [3] SDPA: Enhancing Stateful Forwarding for Software-Defined Networking
    Zhu, Shuyong
    Bi, Jun
    Sun, Chen
    Wu, Chenghui
    Hu, Hongxin
    [J]. 2015 IEEE 23RD INTERNATIONAL CONFERENCE ON NETWORK PROTOCOLS (ICNP), 2015, : 323 - 333
  • [4] Addressing Spoofed DDoS Attacks in Software-defined Networking
    Swami, Rochak
    Dave, Mayank
    Ranga, Virender
    [J]. 2021 6TH INTERNATIONAL CONFERENCE FOR CONVERGENCE IN TECHNOLOGY (I2CT), 2021,
  • [5] Towards DDoS detection mechanisms in Software-Defined Networking
    Cui, Yunhe
    Qian, Qing
    Guo, Chun
    Shen, Guowei
    Tian, Youliang
    Xing, Huanlai
    Yan, Lianshan
    [J]. JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2021, 190
  • [6] SDPA: Toward a Stateful Data Plane in Software-Defined Networking
    Sun, Chen
    Bi, Jun
    Chen, Haoxian
    Hu, Hongxin
    Zheng, Zhilong
    Zhu, Shuyong
    Wu, Chenghui
    [J]. IEEE-ACM TRANSACTIONS ON NETWORKING, 2017, 25 (06) : 3294 - 3308
  • [7] StateSec: Stateful Monitoring for DDoS Protection in Software Defined Networks
    Boite, Julien
    Nardin, Pierre-Alexis
    Rebecchi, Filippo
    Bouet, Mathieu
    Conan, Vania
    [J]. 2017 IEEE CONFERENCE ON NETWORK SOFTWARIZATION (IEEE NETSOFT), 2017,
  • [8] HTTP DDoS flooding attack mitigation in software-defined networking
    Park, Sungho
    Kim, Youngjun
    Choi, Hyungoo
    Kyung, Yeunwoong
    Park, Jinwoo
    [J]. IEICE Transactions on Information and Systems, 2021, E104D (09) : 1496 - 1499
  • [9] HTTP DDoS Flooding Attack Mitigation in Software-Defined Networking
    Park, Sungho
    Kim, Youngjun
    Choi, Hyungoo
    Kyung, Yeunwoong
    Park, Jinwoo
    [J]. IEICE TRANSACTIONS ON INFORMATION AND SYSTEMS, 2021, E104D (09): : 1496 - 1499
  • [10] Joint DDoS detection system based on software-defined networking
    Song, Yubo
    Yang, Huiwen
    Wu, Wei
    Hu, Aiqun
    Gao, Shang
    [J]. Qinghua Daxue Xuebao/Journal of Tsinghua University, 2019, 59 (01): : 28 - 35