Detection and Prevention of DoS attacks in Software-Defined Cloud Networks

被引:0
|
作者
Rengaraju, Perumalraja [1 ]
Ramanan, Raja, V [1 ]
Lung, Chung-Horng [2 ]
机构
[1] Velammal Coll Engn & Technol, Dept IT, Madurai, Tamil Nadu, India
[2] Carleton Univ, Dept Syst & Comp Engn, Ottawa, ON, Canada
关键词
SDN; OFP; DDoS; Firewall and IPS;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
One of the recent focuses in Cloud Computing networks is Software Defined Clouds (SDC), where the Software-Defined Networking (SDN) technology is combined with the traditional Cloud network. SDC is aimed to create an effective Cloud environment by extending the virtualization concept to all resources. In that, the control plane is decoupled from the data plane in a network device and controlled by the centralized controller using the OpenFlow Protocol (OFP). As the centralized controller performs all control functions in a network, it requires strong security. Already, Cloud Computing faces many security challenges. Most vulnerable attacks in SDC is Denial-of-Service (DoS) and Distributed DoS (DDoS) attacks. To overcome the DoS attacks, we propose a distributed Firewall with Intrusion Prevention System (IPS) for SDC. The proposed distributed security mechanism is investigated for two DoS attacks, ICMP and SYN flooding attacks for different network scenarios. From the simulation results and discussion, we showed that the distributed Firewall with IPS security detects and prevents the DoS attack effectively.
引用
收藏
页码:217 / 223
页数:7
相关论文
共 50 条
  • [11] Software-Defined Networks Meet Cloud Computing
    Linthicum, David S.
    [J]. IEEE CLOUD COMPUTING, 2016, 3 (03): : 8 - 10
  • [12] SecSDN-Cloud: Defeating Vulnerable Attacks Through Secure Software-Defined Networks
    Abdulqadder, Ihsan H.
    Zou, Deqing
    Aziz, Israa T.
    Yuan, Bin
    Li, Weiming
    [J]. IEEE ACCESS, 2018, 6 : 8292 - 8301
  • [13] Zero-Day Attack Detection and Prevention in Software-Defined Networks
    Al-Rushdan, Huthifh
    Shurman, Mohammad
    Alnabelsi, Sharhabeel H.
    Althebyan, Qutaibah
    [J]. 2019 INTERNATIONAL ARAB CONFERENCE ON INFORMATION TECHNOLOGY (ACIT), 2019, : 278 - 282
  • [14] Detecting Link Fabrication Attacks in Software-Defined Networks
    Smyth, Dylan
    McSweeney, Sean
    O'Shea, Donna
    Cionca, Victor
    [J]. 2017 26TH INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATION AND NETWORKS (ICCCN 2017), 2017,
  • [15] Identifier Binding Attacks and Defenses in Software-Defined Networks
    Jero, Samuel
    Koch, William
    Skowyra, Richard
    Okhravi, Hamed
    Nita-Rotaru, Cristina
    Bigelow, David
    [J]. PROCEEDINGS OF THE 26TH USENIX SECURITY SYMPOSIUM (USENIX SECURITY '17), 2017, : 415 - 432
  • [16] SPHINX: Detecting Security Attacks in Software-Defined Networks
    Dhawan, Mohan
    Poddar, Rishabh
    Mahajan, Kshiteej
    Mann, Vijay
    [J]. 22ND ANNUAL NETWORK AND DISTRIBUTED SYSTEM SECURITY SYMPOSIUM (NDSS 2015), 2015,
  • [17] Mitigating Timing Side-Channel Attacks in Software-Defined Networks: Detection and Response
    Shoaib, Faizan
    Chow, Yang-Wai
    Vlahu-Gjorgievska, Elena
    Nguyen, Chau
    [J]. TELECOM, 2023, 4 (04): : 877 - 900
  • [18] Intrusion Prevention Scheme Against Rank Attacks for Software-Defined Low Power IoT Networks
    Miranda, Christian
    Kaddoum, Georges
    Boukhtouta, Amine
    Madi, Taous
    Alameddine, Hyame Assem
    [J]. IEEE ACCESS, 2022, 10 : 129970 - 129984
  • [19] Effective Topology Tampering Attacks and Defenses in Software-Defined Networks
    Skowyra, Richard
    Xu, Lei
    Gu, Guofei
    Dedhia, Veer
    Hobson, Thomas
    Okhravi, Hamed
    Landry, James
    [J]. 2018 48TH ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS (DSN), 2018, : 374 - 385
  • [20] A Testbed for the Evaluation of Denial of Service Attacks in Software-Defined Networks
    Wright, Andrea P.
    Ghani, Nasir
    [J]. 2019 IEEE SOUTHEASTCON, 2019,