A Novel Feature-Based DDoS Detection and Mitigation Scheme in SDN Controller Using Queueing Theory

被引:7
|
作者
Tahmasebi, Ava [1 ]
Salahi, Ahmad [2 ]
Pourmina, Mohammad Ali [1 ]
机构
[1] Islamic Azad Univ, Fac Mech Elect & Comp Engn, Sci & Res Branch, Tehran, Iran
[2] Iran Telecommun Res Ctr, Commun Technol Inst, Tehran, Iran
关键词
Software defined network (SDN); Feature extraction; Distributed denial of service (DDoS); Queueing theory; Controller utilization; ATTACK;
D O I
10.1007/s11277-020-07954-3
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
Software defined network (SDN) has attracted great interests as an emergent paradigm which aims to centralize the configuration of network devices by decoupling control layer and data layer. One considerable challenge in SDN is to protect against multiple attacks generated by distributed denial of service (DDoS) bots which attempt to make SDN controllers unavailable. The goal of this research is to propose a novel detect and mitigate DDoS attack in SDN controllers using traffic monitoring. Besides the advantages of queueing theory based model is exploited to evaluate the arrival flows and leveraging robust features and entropy, a distance-based classification is designed accurately to detect malicious packets from legitimate packets. The experimental results vividly demonstrate that our proposed detection scheme effectively yields high accuracy as well as high-efficiency controller utilization.
引用
收藏
页码:1985 / 2006
页数:22
相关论文
共 50 条
  • [1] A Novel Feature-Based DDoS Detection and Mitigation Scheme in SDN Controller Using Queueing Theory
    Ava Tahmasebi
    Ahmad Salahi
    Mohammad Ali Pourmina
    [J]. Wireless Personal Communications, 2021, 117 : 1985 - 2006
  • [2] Time-based DDoS Detection and Mitigation for SDN Controller
    Dharma, I. Gde N.
    Muthohar, M. Fiqri
    Prayuda, Alvin J. D.
    Priagung, K.
    Choi, Deokjai
    [J]. 2015 17TH ASIA-PACIFIC NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM APNOMS, 2015, : 550 - 553
  • [3] A Machine Learning Based Detection and Mitigation of the DDOS Attack by Using SDN Controller Framework
    M. Revathi
    V. V. Ramalingam
    B. Amutha
    [J]. Wireless Personal Communications, 2022, 127 (3) : 2417 - 2441
  • [4] A Machine Learning Based Detection and Mitigation of the DDOS Attack by Using SDN Controller Framework
    Revathi, M.
    Ramalingam, V. V.
    Amutha, B.
    [J]. WIRELESS PERSONAL COMMUNICATIONS, 2022, 127 (03) : 2417 - 2441
  • [5] DoubleTrApp: A Weak Vertex Cover based DDoS Detection and Mitigation scheme using SDN approach
    Bardalai, Priyanka
    Medhi, Nabajyoti
    Chakraborty, Swarnendu Kumar
    [J]. 13TH IEEE INTERNATIONAL CONFERENCE ON ADVANCED NETWORKS AND TELECOMMUNICATION SYSTEMS (IEEE ANTS), 2019,
  • [6] SDN Based Collaborative Scheme for Mitigation of DDoS Attacks
    Hameed, Sufian
    Khan, Hassan Ahmed
    [J]. FUTURE INTERNET, 2018, 10 (03)
  • [7] A DDoS Attack Mitigation Scheme in ISP Networks Using Machine Learning Based on SDN
    Nguyen Ngoc Tuan
    Pham Huy Hung
    Nguyen Danh Nghia
    Nguyen Van Tho
    Trung Van Phan
    Nguyen Huu Thanh
    [J]. ELECTRONICS, 2020, 9 (03)
  • [8] IoT-Based DDoS Attack Detection and Mitigation Using the Edge of SDN
    Yang, Yinqi
    Wang, Jian
    Zhai, Baoqin
    Liu, Jiqiang
    [J]. CYBERSPACE SAFETY AND SECURITY, PT II, 2019, 11983 : 3 - 17
  • [9] DDoS Attacks Detection and Mitigation in SDN using Machine Learning
    Rahman, Obaid
    Quraishi, Mohammad Ali Gauhar
    Lung, Chung-Horng
    [J]. 2019 IEEE WORLD CONGRESS ON SERVICES (IEEE SERVICES 2019), 2019, : 184 - 189
  • [10] TDDAD: Time-Based Detection and Defense Scheme Against DDoS Attack on SDN Controller
    Cui, Jie
    He, Jiantao
    Xu, Yan
    Zhong, Hong
    [J]. INFORMATION SECURITY AND PRIVACY, 2018, 10946 : 649 - 665