Defense mechanisms against DDoS attack based on entropy in SDN-cloud using POX controller

被引:123
|
作者
Mishra, Anupama [1 ]
Gupta, Neena [1 ]
Gupta, B. B. [2 ,3 ,4 ]
机构
[1] Gurukul Kangri Vishwavidyalaya, Dept Comp Sci, Haridwar, India
[2] Niat Inst Technol Kurukshetra, Dept Comp Engn, Kurukshetra 136119, Haryana, India
[3] Asia Univ, Dept Comp Sci & Informat Engn, Taichung, Taiwan
[4] Macquarie Univ, Sydney, NSW 2109, Australia
关键词
Cloud computing; DDoS; Entropy; Mininet; POX controller; Software defined network; SECURITY; PRIVACY;
D O I
10.1007/s11235-020-00747-w
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
Software defined networks (SDNs) in a combination of cloud computing are the best amalgamation for the researchers and industry. Though, these unique networking paradigms have been accepted world widely, they are hampered by various security threats. Among all the threats, the attack, Distributed Denial-of-Service (DDoS) is the most severe attack into the SDN-Cloud. In spite of, so many developments in tools and technology, it is still hard to detect the DDoS attack. Therefore, till now there is no efficient solution to cope up with this problem. In our research work, we proposed a defensive mechanism for DDoS attacks that is based on variations in entropy between DDoS attack and a normal traffic with a low computational overhead. We also proposed a mitigation technique to reduce the severity of the attack. On comparing with the existing DDoS mechanisms, our proposed method holds three advantages as (i) detection rate is high, (ii) false positive rate is low and (iii) the mitigation ability. Simulations are carried out in mininet emulator with POX controller and open flow switches at different attack strength. Our proposed mechanism has achieved a high detection rate with 98.2% over variable attack rate along with 0.04% false positive rate.
引用
收藏
页码:47 / 62
页数:16
相关论文
共 50 条
  • [21] Mitigating HTTP GET FLOOD DDoS attack using an SDN controller
    Sanjeetha, R.
    Shastry, K. N. Ajay
    Chetan, H. R.
    Kanavalli, Anita
    2020 5TH IEEE INTERNATIONAL CONFERENCE ON RECENT TRENDS ON ELECTRONICS, INFORMATION, COMMUNICATION & TECHNOLOGY (RTEICT-2020), 2020, : 6 - 10
  • [22] An SVM Based DDoS Attack Detection Method for Ryu SDN Controller
    Mehr, Shideh Yavary
    Ramamurthy, Byrav
    CONEXT'19 COMPANION: PROCEEDINGS OF THE 15TH INTERNATIONAL CONFERENCE ON EMERGING NETWORKING EXPERIMENTS AND TECHNOLOGIES, 2019, : 72 - 73
  • [23] A Confidence Interval Based Filtering Against DDoS Attack in Cloud Environment: A Confidence Interval Against DDoS Attack in the Cloud
    Haddadi, Mohamed
    Beghdad, Rachid
    INTERNATIONAL JOURNAL OF INFORMATION SECURITY AND PRIVACY, 2020, 14 (04) : 42 - 56
  • [24] DDoS Attack Detection Model Based on Information Entropy and DNN in SDN
    Zhang L.
    Wang J.
    Jisuanji Yanjiu yu Fazhan/Computer Research and Development, 2019, 56 (05): : 909 - 918
  • [25] An Efficient Defense Scheme Against SIP DoS Attack in SDN Using Cloud SFW
    Liu, ZengGuang
    Yin, XiaoChun
    Lee, Hoon Jae
    2014 NINTH ASIA JOINT CONFERENCE ON INFORMATION SECURITY (ASIA JCIS), 2014, : 52 - 55
  • [26] JESS: Joint Entropy-Based DDoS Defense Scheme in SDN
    Kalkan, Kubra
    Altay, Levent
    Gur, Gurkan
    Alagoz, Fatih
    IEEE JOURNAL ON SELECTED AREAS IN COMMUNICATIONS, 2018, 36 (10) : 2358 - 2372
  • [27] DDoS attack Defense Framework for Cloud using Fog Computing
    Deepali
    Bhushan, Kriti
    2017 2ND IEEE INTERNATIONAL CONFERENCE ON RECENT TRENDS IN ELECTRONICS, INFORMATION & COMMUNICATION TECHNOLOGY (RTEICT), 2017, : 534 - 538
  • [28] Real-time DDoS Attack Defense System in SDN Using LSSOM
    Liu, Shijin
    Fukuda, Hiroaki
    Leger, Paul
    2023 26TH CONFERENCE ON INNOVATION IN CLOUDS, INTERNET AND NETWORKS AND WORKSHOPS, ICIN, 2023,
  • [29] DDoS attack detection and defense based on hybrid deep learning model in SDN
    Li C.
    Wu Y.
    Qian Z.
    Sun Z.
    Wang W.
    2018, Editorial Board of Journal on Communications (39): : 176 - 187
  • [30] Collaborative Defense Method Against DDoS Attacks on SDN-Architected Cloud Servers
    Zhang, Yiying
    Xu, Yao
    Han, Longzhe
    Liang, Kun
    Li, Wenjing
    ADVANCED INTELLIGENT COMPUTING TECHNOLOGY AND APPLICATIONS, PT IV, ICIC 2024, 2024, 14865 : 362 - 370