BSD-Guard: A Collaborative Blockchain-Based Approach for Detection and Mitigation of SDN-Targeted DDoS Attacks

被引:8
|
作者
Jiang, Shanqing [1 ,2 ,3 ]
Yang, Lin [2 ]
Gao, Xianming [2 ]
Zhou, Yuyang [1 ,3 ,4 ]
Feng, Tao [1 ,2 ]
Song, Yanbo [5 ]
Liu, Kexian [6 ]
Cheng, Guang [1 ,3 ,4 ]
机构
[1] Southeast Univ, Sch Cyber Sci & Engn, Nanjing, Peoples R China
[2] PLA Acad Mil Sci, Inst Syst Engn, Natl Key Lab Sci & Technol Informat Syst Secur, Beijing, Peoples R China
[3] Purple Mt Labs, Nanjing, Peoples R China
[4] Jiangsu Prov Engn Res Ctr Secur Ubiquitous Networ, Nanjing, Peoples R China
[5] Xidian Univ, State Key Lab Integrated Serv Networks, Xian, Peoples R China
[6] Beijing Univ Posts & Telecommun, Sch Comp Sci, Beijing, Peoples R China
基金
中国国家自然科学基金;
关键词
SOFTWARE; DOS;
D O I
10.1155/2022/1608689
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Software-Defined Networking (SDN) enhances the flexibility and programmability of networks by separating control plane and data plane. The logically centralized control mechanism makes the control plane vulnerable in both single and multiple controller scenarios. Malicious third parties can exploit vulnerabilities of reactive forwarding mode to launch distributed denial-of-service (DDoS) attacks against SDN controllers. Unfortunately, existing DoS/DDoS solutions under single controller can not afford effective performance under multiple controllers due to the absence of cooperative detection and mitigation. To solve the above problem, we propose a blockchain-based SDN-targeted DDoS defense framework (BSD-Guard) that can provide cooperative detection and mitigation mechanism to protect SDN controllers. BSD-Guard introduces a blockchain-based secure middle plane between control plane and data plane. The secure middle plane calculates the suspect rate of new flows based on the collected packets' information and reports suspect lists to blockchain for immutably storing and sharing. Besides, the smart contract deployed on blockchain in advance constitutes collaborative defense strategies based on the suspect lists reported from multiple SDN domains. When receiving defense strategies, the secure middle plane converts them to specific flow table actions and installs actions into relevant switches. The experimental results indicate that BSD-Guard can efficiently detect DoS/DDoS attacks in multiple controllers scenario and issue precise defensive strategies near the source of attack by identifying the attack path.
引用
收藏
页数:16
相关论文
共 26 条
  • [1] SDN Based Collaborative Scheme for Mitigation of DDoS Attacks
    Hameed, Sufian
    Khan, Hassan Ahmed
    [J]. FUTURE INTERNET, 2018, 10 (03)
  • [2] Neural Network-Based Approach for Detection and Mitigation of DDoS Attacks in SDN Environments
    Hannache, Oussama
    Batouche, Mohamed Chaouki
    [J]. INTERNATIONAL JOURNAL OF INFORMATION SECURITY AND PRIVACY, 2020, 14 (03) : 50 - 71
  • [3] SDN-based detection and mitigation of DDoS attacks on smart homes
    Garba, Usman Haruna
    Toosi, Adel N.
    Pasha, Muhammad Fermi
    Khan, Suleman
    [J]. COMPUTER COMMUNICATIONS, 2024, 221 : 29 - 41
  • [4] DNS Amplification Based DDoS Attacks in SDN Environment: Detection and Mitigation
    Gupta, Vishal
    Kochar, Amrit
    Saharan, Shail
    Kulshrestha, Rakhee
    [J]. 2019 IEEE 4TH INTERNATIONAL CONFERENCE ON COMPUTER AND COMMUNICATION SYSTEMS (ICCCS 2019), 2019, : 473 - 478
  • [5] FBA-SDN: A Federated Byzantine Approach for Blockchain-based Collaborative Intrusion Detection in Edge SDN
    Hayes, John
    Aneiba, Adel
    Gaber, Mohamed
    Islam, Md Shantanu
    Abozariba, Raouf
    [J]. 2023 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS WORKSHOPS, ICC WORKSHOPS, 2023, : 427 - 433
  • [6] Detection and Mitigation of DoS and DDoS Attacks in IoT-Based Stateful SDN: An Experimental Approach
    Galeano-Brajones, Jesus
    Carmona-Murillo, Javier
    Valenzuela-Valdes, Juan F.
    Luna-Valero, Francisco
    [J]. SENSORS, 2020, 20 (03)
  • [7] IQR-based approach for DDoS detection and mitigation in SDN
    Swami, Rochak
    Dave, Mayank
    Ranga, Virender
    [J]. DEFENCE TECHNOLOGY, 2023, 25 : 76 - 87
  • [8] IQR-based approach for DDoS detection and mitigation in SDN
    Rochak Swami
    Mayank Dave
    Virender Ranga
    [J]. Defence Technology, 2023, 25 (07) : 76 - 87
  • [9] SDN-Based Intrusion Detection System for Early Detection and Mitigation of DDoS Attacks
    Manso, Pedro
    Moura, Jose
    Serrao, Carlos
    [J]. INFORMATION, 2019, 10 (03)
  • [10] Detection and mitigation of DDoS attacks based on multi-dimensional characteristics in SDN
    Kun Wang
    Yu Fu
    Xueyuan Duan
    Taotao Liu
    [J]. Scientific Reports, 14 (1)