A systematic review on distributed denial of service attack defense mechanisms in programmable networks

被引:13
|
作者
Dalmazo, Bruno L. [1 ]
Marques, Jonatas A. [2 ]
Costa, Lucas R. [3 ]
Bonfim, Michel S. [4 ]
Carvalho, Ranyelson N. [3 ]
da Silva, Anderson S. [2 ]
Fernandes, Stenio [4 ]
Bordim, Jacir L. [3 ]
Alchieri, Eduardo [3 ]
Schaeffer-Filho, Alberto [2 ]
Paschoal Gaspary, Luciano [2 ]
Cordeiro, Weverton [2 ]
机构
[1] Fed Univ Rio Grande, Ctr Ciencias Comp, Porto Alegre, RS, Brazil
[2] Univ Fed Rio Grande do Sul, Inst Informat, BR-90040060 Porto Alegre, RS, Brazil
[3] Univ Brasilia, Comp Dept, Brasilia, DF, Brazil
[4] Univ Fed Pernambuco, Ctr Informat, Recife, PE, Brazil
基金
美国国家科学基金会;
关键词
OF-THE-ART; DDOS ATTACKS; DATA PLANE; SDN; MITIGATION; FRAMEWORK; SCHEME; CHALLENGES; DIAGNOSIS; INTERNET;
D O I
10.1002/nem.2163
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Design flaws and vulnerabilities inherent to network protocols, devices, and services make Distributed Denial of Service (DDoS) a persisting threat in the cyberspace, despite decades of research efforts in the area. The historical vertical integration of traditional IP networks limited the solution space, forcing researchers to tweak network protocols while maintaining global compatibility and proper service to legitimate flows. The advent of Software-Defined Networking (SDN) and advances in Programmable Data Planes (PDP) changed the state of affairs and brought novel possibilities to deal with such attacks. In summary, the ability of bringing together network intelligence to a control plane, and offloading flow processing tasks to the forwarding plane, opened up interesting opportunities for network security researchers unlike ever. In this article, we dive into recent research that relies on SDN and PDP to detect, mitigate, and prevent DDoS attacks. Our literature review takes into account the SDN layered view as defined in RFC7426 and focuses on the data, control, and application planes. We follow a systematic methodology to capture related articles and organize them into a taxonomy of DDoS defense mechanisms focusing on three facets: activity level, deployment location, and cooperation degree. From the analysis of existing work, we also highlight key research gaps that may foster future research in the field.
引用
收藏
页数:31
相关论文
共 50 条
  • [1] A Defense Mechanism for Distributed Denial of Service Attack in Software-Defined Networks
    Luo, Shibo
    Wu, Jun
    Li, Jianhua
    Pei, Bei
    [J]. 2015 NINTH INTERNATIONAL CONFERENCE ON FRONTIER OF COMPUTER SCIENCE AND TECHNOLOGY FCST 2015, 2015, : 324 - 328
  • [2] A Survey on Resource Inflated Denial of Service Attack Defense Mechanisms
    Chand, Nithun O.
    Mathivanan, S.
    [J]. PROCEEDINGS OF 2016 ONLINE INTERNATIONAL CONFERENCE ON GREEN ENGINEERING AND TECHNOLOGIES (IC-GET), 2016,
  • [3] Comprehensive Review of Artificial Intelligence and Statistical Approaches in Distributed Denial of Service Attack and Defense Methods
    Khalaf, Bashar Ahmed
    Mostafa, Salama A.
    Mustapha, Aida
    Mohammed, Mazin Abed
    Abduallah, Wafaa Mustafa
    [J]. IEEE ACCESS, 2019, 7 : 51691 - 51713
  • [4] Game-based Simulation of Distributed Denial of Service (DDoS) Attack and Defense Mechanisms of Critical Infrastructures
    Poisel, Rainer
    Rybnicek, Marlies
    Tjoa, Simon
    [J]. 2013 IEEE 27TH INTERNATIONAL CONFERENCE ON ADVANCED INFORMATION NETWORKING AND APPLICATIONS (AINA), 2013, : 114 - 120
  • [5] Characterization of defense mechanisms against distributed denial of service attacks
    Chen, LC
    Longstaff, TA
    Carley, KM
    [J]. COMPUTERS & SECURITY, 2004, 23 (08) : 665 - 678
  • [6] Defense mechanisms against Distributed Denial of Service attacks : A survey
    Manavi, Mousa Taghizadeh
    [J]. COMPUTERS & ELECTRICAL ENGINEERING, 2018, 72 : 26 - 38
  • [7] Smart defense against distributed Denial of service attack in IoT networks using supervised learning classifiers
    Gupta, B. B.
    Chaudhary, Pooja
    Chang, Xiaojun
    Nedjah, Nadia
    [J]. COMPUTERS & ELECTRICAL ENGINEERING, 2022, 98
  • [8] Distributed Denial of Service (DDoS) Attack in Cloud- Assisted Wireless Body Area Networks: A Systematic Literature Review
    Rabia Latif
    Haider Abbas
    Saïd Assar
    [J]. Journal of Medical Systems, 2014, 38
  • [9] Distributed Denial of Service (DDoS) Attack in Cloud-Assisted Wireless Body Area Networks: A Systematic Literature Review
    Latif, Rabia
    Abbas, Haider
    Assar, Said
    [J]. JOURNAL OF MEDICAL SYSTEMS, 2014, 38 (11)
  • [10] MECPASS: Distributed Denial of Service Defense Architecture for Mobile Networks
    Van Linh Nguyen
    Lin, Po-Ching
    Hwang, Ren-Hung
    [J]. IEEE NETWORK, 2018, 32 (01): : 118 - 124