Defense mechanisms against DDoS attack based on entropy in SDN-cloud using POX controller

被引:123
|
作者
Mishra, Anupama [1 ]
Gupta, Neena [1 ]
Gupta, B. B. [2 ,3 ,4 ]
机构
[1] Gurukul Kangri Vishwavidyalaya, Dept Comp Sci, Haridwar, India
[2] Niat Inst Technol Kurukshetra, Dept Comp Engn, Kurukshetra 136119, Haryana, India
[3] Asia Univ, Dept Comp Sci & Informat Engn, Taichung, Taiwan
[4] Macquarie Univ, Sydney, NSW 2109, Australia
关键词
Cloud computing; DDoS; Entropy; Mininet; POX controller; Software defined network; SECURITY; PRIVACY;
D O I
10.1007/s11235-020-00747-w
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
Software defined networks (SDNs) in a combination of cloud computing are the best amalgamation for the researchers and industry. Though, these unique networking paradigms have been accepted world widely, they are hampered by various security threats. Among all the threats, the attack, Distributed Denial-of-Service (DDoS) is the most severe attack into the SDN-Cloud. In spite of, so many developments in tools and technology, it is still hard to detect the DDoS attack. Therefore, till now there is no efficient solution to cope up with this problem. In our research work, we proposed a defensive mechanism for DDoS attacks that is based on variations in entropy between DDoS attack and a normal traffic with a low computational overhead. We also proposed a mitigation technique to reduce the severity of the attack. On comparing with the existing DDoS mechanisms, our proposed method holds three advantages as (i) detection rate is high, (ii) false positive rate is low and (iii) the mitigation ability. Simulations are carried out in mininet emulator with POX controller and open flow switches at different attack strength. Our proposed mechanism has achieved a high detection rate with 98.2% over variable attack rate along with 0.04% false positive rate.
引用
收藏
页码:47 / 62
页数:16
相关论文
共 50 条
  • [31] A cooperative DDoS attack detection scheme based on entropy and ensemble learning in SDN
    Shanshan Yu
    Jicheng Zhang
    Ju Liu
    Xiaoqing Zhang
    Yafeng Li
    Tianfeng Xu
    EURASIP Journal on Wireless Communications and Networking, 2021
  • [32] A DDoS Attack Detection Method Based on Information Entropy and Deep Learning in SDN
    Wang, Lu
    Liu, Ying
    PROCEEDINGS OF 2020 IEEE 4TH INFORMATION TECHNOLOGY, NETWORKING, ELECTRONIC AND AUTOMATION CONTROL CONFERENCE (ITNEC 2020), 2020, : 1084 - 1088
  • [33] A cooperative DDoS attack detection scheme based on entropy and ensemble learning in SDN
    Yu, Shanshan
    Zhang, Jicheng
    Liu, Ju
    Zhang, Xiaoqing
    Li, Yafeng
    Xu, Tianfeng
    EURASIP JOURNAL ON WIRELESS COMMUNICATIONS AND NETWORKING, 2021, 2021 (01)
  • [34] Using SDN Approach to Secure Cloud Servers Against Flooding Based DDoS Attacks
    Guesmi, Houda
    Saidane, Leila Azouz
    2017 25TH INTERNATIONAL CONFERENCE ON SYSTEMS ENGINEERING (ICSENG), 2017, : 309 - 315
  • [35] Detection and Defense of DDoS Attack and Flash Events by Using Shannon Entropy
    Chiu, Shih-Ting
    Susanto, Heru
    Leu, Fang-Yie
    INNOVATIVE MOBILE AND INTERNET SERVICES IN UBIQUITOUS COMPUTING, IMIS-2022, 2022, 496 : 307 - 314
  • [36] XGBoost Classifier for DDoS Attack Detection and Analysis in SDN-based Cloud
    Chen, Zhuo
    Jiang, Fu
    Cheng, Yijun
    Gu, Xin
    Liu, Weirong
    Peng, Jun
    2018 IEEE INTERNATIONAL CONFERENCE ON BIG DATA AND SMART COMPUTING (BIGCOMP), 2018, : 251 - 256
  • [37] Efficient DDoS attack detection and prevention scheme based on SDN in cloud environment
    He H.
    Hu Y.
    Zheng L.
    Xue Z.
    He, Heng (heheng@wust.edu.cn), 2018, Editorial Board of Journal on Communications (39): : 139 - 151
  • [38] Multi-Defense Mechanism against DDoS in SDN based CDNi
    Nishat-I-Mowla
    Doh, Inshil
    Chae, Kijoon
    2014 Eighth International Conference on Innovative Mobile and Internet Services in Ubiquitous Computing (IMIS), 2014, : 447 - 451
  • [39] Entropy based earlier detection and mitigation of DDOS attack using stochastic method in SDN_IOT
    Varalakshmi, I.
    Thenmozhi, M.
    Measurement: Sensors, 2025, 39
  • [40] A DDoS attack detection and defense scheme using time-series analysis for SDN
    Fouladi, Ramin Fadaei
    Ermis, Orhan
    Anarim, Emin
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2020, 54 (54)