Detection of DDoS Attacks in Software Defined Networking Using Entropy

被引:13
|
作者
Fan, Cong [1 ,2 ]
Kaliyamurthy, Nitheesh Murugan [2 ]
Chen, Shi [1 ]
Jiang, He [1 ]
Zhou, Yiwen [1 ]
Campbell, Carlene [2 ]
机构
[1] Wuhan Univ Technol, Sch Informat Engn, Wuhan 430070, Peoples R China
[2] Univ Wales Trinity St David, Wales Inst Sci & Art, Swansea SA1 8PH, W Glam, Wales
来源
APPLIED SCIENCES-BASEL | 2022年 / 12卷 / 01期
关键词
software defined networking; entropy; distributed denial of service attacks; SECURITY ISSUES;
D O I
10.3390/app12010370
中图分类号
O6 [化学];
学科分类号
0703 ;
摘要
Featured Application This study proposes a detection method of Distributed Denial of Service attacks in Software Defined Networking, which uses the property of entropy to measure the occurrence of attack behavior in the network. The significance of this study is to quickly and effectively detect Distributed Denial of Service attacks in the Software Defined Networking and protect the SDN controller against security threats. Software Defined Networking (SDN) is one of the most commonly used network architectures in recent years. With the substantial increase in the number of Internet users, network security threats appear more frequently, which brings more concerns to SDN. Distributed denial of Service (DDoS) attacks are one of the most dangerous and frequent attacks in software defined networks. The traditional attack detection method using entropy has some defects such as slow attack detection and poor detection effect. In order to solve this problem, this paper proposed a method of fusion entropy, which detects attacks by measuring the randomness of network events. This method has the advantages of fast attack detection speed and obvious decrease in entropy value. The complementarity of information entropy and log energy entropy is effectively utilized. The experimental results show that the entropy value of the attack scenarios 91.25% lower than normal scenarios, which has greater advantages and significance compared with other attack detection methods.
引用
收藏
页数:16
相关论文
共 50 条
  • [1] Detection and Mitigation of DDoS Attacks Using Conditional Entropy in Software-defined Networking
    Xuanyuan, Ming
    Ramsurrun, Visham
    Seeam, Amar
    [J]. 2019 11TH INTERNATIONAL CONFERENCE ON ADVANCED COMPUTING (ICOAC 2019), 2019, : 66 - 71
  • [2] Entropy-Based Approach to Detect DDoS Attacks on Software Defined Networking Controller
    Aladaileh, Mohammad
    Anbar, Mohammed
    Hasbullah, Iznan H.
    Sanjalawe, Yousef K.
    Chong, Yung-Wey
    [J]. CMC-COMPUTERS MATERIALS & CONTINUA, 2021, 69 (01): : 373 - 391
  • [3] Entropy-based approach to detect DDoS attacks on software defined networking controller
    Aladaileh, Mohammad
    Anbar, Mohammed
    Hasbullah, Iznan H.
    Sanjalawe, Yousef K.
    Chong, Yung-Wey
    [J]. Computers, Materials and Continua, 2021, 69 (01): : 373 - 391
  • [4] Mitigating DDoS Attacks Using OpenFlow-Based Software Defined Networking
    Jonker, Mattijs
    Sperotto, Anna
    [J]. INTELLIGENT MECHANISMS FOR NETWORK CONFIGURATION AND SECURITY, 2015, 9122 : 129 - 133
  • [5] Addressing Spoofed DDoS Attacks in Software-defined Networking
    Swami, Rochak
    Dave, Mayank
    Ranga, Virender
    [J]. 2021 6TH INTERNATIONAL CONFERENCE FOR CONVERGENCE IN TECHNOLOGY (I2CT), 2021,
  • [6] Lightweight solutions to counter DDoS attacks in software defined networking
    Conti, Mauro
    Lal, Chhagan
    Mohammadi, Reza
    Rawat, Umashankar
    [J]. WIRELESS NETWORKS, 2019, 25 (05) : 2751 - 2768
  • [7] Lightweight solutions to counter DDoS attacks in software defined networking
    Mauro Conti
    Chhagan Lal
    Reza Mohammadi
    Umashankar Rawat
    [J]. Wireless Networks, 2019, 25 : 2751 - 2768
  • [8] Review on Detection Techniques against DDoS Attacks on a Software-Defined Networking Controller
    Zubaydi, Haider Dhia
    Anbar, Mohammed
    Wey, Chong Yung
    [J]. 2017 PALESTINIAN INTERNATIONAL CONFERENCE ON INFORMATION AND COMMUNICATION TECHNOLOGY (PICICT), 2017, : 10 - 16
  • [9] An Entropy-Based Distributed DDoS Detection Mechanism in Software-Defined Networking
    Wang, Rui
    Jia, Zhiping
    Ju, Lei
    [J]. 2015 IEEE TRUSTCOM/BIGDATASE/ISPA, VOL 1, 2015, : 310 - 317
  • [10] Automated DDOS attack detection in software defined networking
    Ahuja, Nisha
    Singal, Gaurav
    Mukhopadhyay, Debajyoti
    Kumar, Neeraj
    [J]. JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2021, 187