A Dynamic Hybrid Timeout Method to Secure Flow Tables Against DDoS Attacks in SDN

被引:0
|
作者
Sooden, Balram [1 ]
Abbasi, Mohammad Reza [2 ]
机构
[1] Dr BR Ambedkar Natl Inst Technol, Comp Sci & Engn Dept, Jalandhar, Punjab, India
[2] Panjab Univ, Dept Comp Sci & Applicat, Chandigarh, India
关键词
SDN security; DDoS attacks; Security Service; Flow table;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Distributed Denial of Service attacks are one of the major threats to network-based services today. Software Defined Networks (SDN) has the potential to evolve into a much more secure network paradigm than a traditional network as the whole network is controlled by a central controller having a complete view of the network. Being a considerably new concept, there are certain research problems related to SDN which are still needed to be addressed. Our work focuses on the collection of flow statistics to record the complete current and historical dynamics of the network by the controller to enable it to detect and prevent anomalous behavior in the network. Another research problem addressed in this paper is based on the Ternary Content Addressable Memory (TCAM) limitation of SDN based switches, which can be exploited with malicious hosts generating discrete network flows. To address this problem we propose the Dynamic Hybrid Timeout Method. It uses a blend of idle and hard timeout methods in addition to the Peer Support Strategy to enhance the durability of TCAM memory during flow table overloading DDoS attacks. The simulation results show that the Dynamic Hybrid Timeout Method enhances the performance of the Peer Support Strategy and adds durability in flow table memory utilization.
引用
收藏
页码:29 / 34
页数:6
相关论文
共 50 条
  • [1] Algorithm for Secure Hybrid Cloud Design Against DDoS Attacks
    Bhardwaj, Akashdeep
    Goundar, Sam
    [J]. INTERNATIONAL JOURNAL OF INFORMATION TECHNOLOGY AND WEB ENGINEERING, 2018, 13 (04) : 61 - 77
  • [2] Flow Table Saturation Attack against Dynamic Timeout Mechanisms in SDN
    Shen, Yi
    Wu, Chunming
    Kong, Dezhang
    Cheng, Qiumei
    [J]. APPLIED SCIENCES-BASEL, 2023, 13 (12):
  • [3] Using SDN Approach to Secure Cloud Servers Against Flooding Based DDoS Attacks
    Guesmi, Houda
    Saidane, Leila Azouz
    [J]. 2017 25TH INTERNATIONAL CONFERENCE ON SYSTEMS ENGINEERING (ICSENG), 2017, : 309 - 315
  • [4] Detecting DDoS Attacks in SDN using a Hybrid Method with Entropy and Machine Learning
    Santos-Neto, Marcos J.
    Bordim, Jacir L.
    Alchieri, Eduardo A. P.
    Ishikawa, Edison
    Dourado, Leonardo S.
    [J]. 2022 TENTH INTERNATIONAL SYMPOSIUM ON COMPUTING AND NETWORKING WORKSHOPS, CANDARW, 2022, : 248 - 254
  • [5] Early Detection of DDoS Attacks against SDN Controllers
    Mousavi, Seyed Mohammad
    St-Hilaire, Marc
    [J]. 2015 INTERNATIONAL CONFERENCE ON COMPUTING, NETWORKING AND COMMUNICATIONS (ICNC), 2015, : 77 - 81
  • [6] Defense Mechanisms Against DDoS Attacks in SDN Environment
    Kalkan, Kubra
    Gur, Gurkan
    Alagoz, Fatih
    [J]. IEEE COMMUNICATIONS MAGAZINE, 2017, 55 (09) : 175 - 179
  • [7] An AI based Approach to Secure SDN Enabled Future Avionics Communications Network Against DDoS Attacks
    Ali, Muhammad
    Benamrane, Fouad
    Luong, Doanh Kim
    Hu, Yim-Fun
    Li, Jian-Ping
    Abdo, Kanaan
    [J]. 2019 IEEE/AIAA 38TH DIGITAL AVIONICS SYSTEMS CONFERENCE (DASC), 2019,
  • [8] A Method for DDoS Attacks Prevention Using SDN and NFV
    Shayegan, Mohammad Javad
    Damghanian, Amirreza
    [J]. IEEE ACCESS, 2024, 12 : 108176 - 108184
  • [9] A Security Analysis of a Hybrid Mechanism to Defend DDoS Attacks in SDN
    Jantila, Saksit
    Chaipah, Kornchawal
    [J]. 2016 INTERNATIONAL ELECTRICAL ENGINEERING CONGRESS, IEECON2016, 2016, : 437 - 440
  • [10] A protocol for cluster confirmations of SDN controllers against DDoS attacks
    Iranmanesh, Amir
    Naji, Hamid Reza
    [J]. COMPUTERS & ELECTRICAL ENGINEERING, 2021, 93