An Entropy-Based Distributed DDoS Detection Mechanism in Software-Defined Networking

被引:0
|
作者
Wang, Rui [1 ]
Jia, Zhiping [1 ]
Ju, Lei [1 ]
机构
[1] Shandong Univ, Sch Comp Sci & Technol, Jinan, Peoples R China
基金
高等学校博士学科点专项科研基金;
关键词
SDN; OpenFlow; DDoS; Entropy; ANOMALY DETECTION; MITIGATION;
D O I
10.1109/Trustcom-2015.389
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Software-Defined Networking (SDN) and OpenFlow (OF) protocol have brought a promising architecture for the future networks. However, the centralized control and programmable characteristics also bring a lot of security challenges. Distributed denial-of-service (DDoS) attack is still a security threat to SDN. To detect the DDoS attack in SDN, many researches collect the flow tables from the switch and do the anomaly detection in the controller. But in the large scale network, the collecting process burdens the communication overload between the switches and the controller. Sampling technology may relieve this overload, but it brings a new tradeoff between sampling rate and detection accuracy. In this paper, we first extend a copy of the packet number counter of the flow entry in the OpenFlow table. Based on the flow-based nature of SDN, we design a flow statistics process in the switch. Then, we propose an entropy-based lightweight DDoS flooding attack detection model running in the OF edge switch. This achieves a distributed anomaly detection in SDN and reduces the flow collection overload to the controller. We also give the detailed algorithm which has a small calculation overload and can be easily implemented in SDN software or programmable switch, such as Open vSwitch and NetFPGA. The experimental results show that our detection mechanism can detect the attack quickly and achieve a high detection accuracy with a low false positive rate.
引用
收藏
页码:310 / 317
页数:8
相关论文
共 50 条
  • [1] Joint DDoS detection system based on software-defined networking
    Song, Yubo
    Yang, Huiwen
    Wu, Wei
    Hu, Aiqun
    Gao, Shang
    [J]. Qinghua Daxue Xuebao/Journal of Tsinghua University, 2019, 59 (01): : 28 - 35
  • [2] Detection and Mitigation of DDoS Attacks Using Conditional Entropy in Software-defined Networking
    Xuanyuan, Ming
    Ramsurrun, Visham
    Seeam, Amar
    [J]. 2019 11TH INTERNATIONAL CONFERENCE ON ADVANCED COMPUTING (ICOAC 2019), 2019, : 66 - 71
  • [3] Entropy-Based Approach to Detect DDoS Attacks on Software Defined Networking Controller
    Aladaileh, Mohammad
    Anbar, Mohammed
    Hasbullah, Iznan H.
    Sanjalawe, Yousef K.
    Chong, Yung-Wey
    [J]. CMC-COMPUTERS MATERIALS & CONTINUA, 2021, 69 (01): : 373 - 391
  • [4] Entropy-based approach to detect DDoS attacks on software defined networking controller
    Aladaileh, Mohammad
    Anbar, Mohammed
    Hasbullah, Iznan H.
    Sanjalawe, Yousef K.
    Chong, Yung-Wey
    [J]. Computers, Materials and Continua, 2021, 69 (01): : 373 - 391
  • [5] Towards DDoS detection mechanisms in Software-Defined Networking
    Cui, Yunhe
    Qian, Qing
    Guo, Chun
    Shen, Guowei
    Tian, Youliang
    Xing, Huanlai
    Yan, Lianshan
    [J]. JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2021, 190
  • [6] A Novel OpenFlow-Based DDoS Flooding Attack Detection and Response Mechanism in Software-Defined Networking
    Wang, Rui
    Zhang, Zhiyong
    Ju, Lei
    Jia, Zhiping
    [J]. INTERNATIONAL JOURNAL OF INFORMATION SECURITY AND PRIVACY, 2015, 9 (03) : 21 - 40
  • [7] Detection of DDoS Attacks in Software Defined Networking Using Entropy
    Fan, Cong
    Kaliyamurthy, Nitheesh Murugan
    Chen, Shi
    Jiang, He
    Zhou, Yiwen
    Campbell, Carlene
    [J]. APPLIED SCIENCES-BASEL, 2022, 12 (01):
  • [8] DDoS protection with stateful software-defined networking
    Rebecchi, Filippo
    Boite, Julien
    Nardin, Pierre-Alexis
    Bouet, Mathieu
    Conan, Vania
    [J]. INTERNATIONAL JOURNAL OF NETWORK MANAGEMENT, 2019, 29 (01)
  • [9] Software-defined Networking-based DDoS Defense Mechanisms
    Swami, Rochak
    Dave, Mayank
    Ranga, Virender
    [J]. ACM COMPUTING SURVEYS, 2019, 52 (02)
  • [10] Feature Selection and 1DCNN-based DDOS Detection in Software-Defined Networking
    Almi'ani, Noor
    Anbar, Mohammed
    Karuppayah, Shankar
    Sanjalawe, Yousef
    Alrababah, Hamza
    Abu Zwayed, Fadi
    Hasbullah, Iznan H.
    [J]. ENGINEERING LETTERS, 2024, 32 (07) : 1529 - 1544