A Cost-Effective MTD Approach for DDoS Attacks in Software-Defined Networks

被引:3
|
作者
Javadpour, Amir [1 ]
Ja'fari, Forough [2 ]
Taleb, Tarik [1 ]
Shojafar, Mohammad [3 ]
机构
[1] Univ Oulu, Fac Informat Technol & Elect Engn, FIN-90570 Oulu, Finland
[2] Sharif Univ Technol, Dept Comp Engn, Tehran, Iran
[3] Univ Surrey, Inst Commun Syst ICS, 5GIC & 6GIC, Guildford GU27XH, Surrey, England
基金
欧盟地平线“2020”; 芬兰科学院;
关键词
Software-defined networking (SDN); Moving Target Defense (MTD); Distributed Denial of Service (DDoS); Cost-effective; Edge-based Shuffling; Low-complexity; MOVING TARGET DEFENSE;
D O I
10.1109/GLOBECOM48099.2022.10000603
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Protecting large-scale networks, especially Software-Defined Networks (SDNs), against distributed attacks in a cost-effective manner plays a prominent role in cybersecurity. One of the pervasive approaches to plug security holes and prevent vulnerabilities from being exploited is Moving Target Defense (MTD), which can be efficiently implemented in SDN as it needs comprehensive and proactive network monitoring. The critical key in MTD is to shuffle the least number of hosts with an acceptable security impact and keep the shuffling frequency low. In this paper, we have proposed an SDN-oriented Cost-effective Edge-based MTD Approach (SCEMA) to mitigate Distributed Denial of Service (DDoS) attacks with a lower cost by shuffling an optimized set of hosts have the highest number of connections to the critical servers. These connections are named edges from a graph-theoretical point of view. We have designed a system based on SCEMA and simulated it in Mininet. The results show that SCEMA has lower (52..52 58. %) complexity than the previous related MTD methods with improving the security level by.14.32.%.
引用
收藏
页码:4173 / 4178
页数:6
相关论文
共 50 条
  • [41] CeMon: A cost-effective flow monitoring system in software defined networks
    Su, Zhiyang
    Wang, Ting
    Xia, Yu
    Hamdi, Mounir
    [J]. COMPUTER NETWORKS, 2015, 92 : 101 - 115
  • [42] SD-Anti-DDoS: Fast and efficient DDoS defense in software-defined networks
    Cui, Yunhe
    Yan, Lianshan
    Li, Saifei
    Xing, Huanlai
    Pan, Wei
    Zhu, Jian
    Zheng, Xiaoyang
    [J]. JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2016, 68 : 65 - 79
  • [43] Bandwidth Control Mechanism and Extreme Gradient Boosting Algorithm for Protecting Software-Defined Networks Against DDoS Attacks
    Alamri, Hassan A.
    Thayananthan, Vijey
    [J]. IEEE ACCESS, 2020, 8 : 194269 - 194288
  • [44] SDNTruth: Innovative DDoS Detection Scheme for Software-Defined Networks (SDN)
    Tiago Linhares
    Ahmed Patel
    Ana Luiza Barros
    Marcial Fernandez
    [J]. Journal of Network and Systems Management, 2023, 31
  • [45] Using Machine Learning and Software-Defined Networking to Detect and Mitigate DDoS Attacks in Fiber-Optic Networks
    Alwabisi, Sulaiman
    Ouni, Ridha
    Saleem, Kashif
    [J]. ELECTRONICS, 2022, 11 (23)
  • [46] AALLA: Attack-Aware Logical Link Assignment Cost-Minimization Model for Protecting Software-Defined Networks against DDoS Attacks
    Ali, Sameer
    Tan, Saw Chin
    Lee, Ching Kwang
    Yusoff, Zulfadzli
    Haque, Muhammad Reazul
    Mylonas, Alexios
    Pitropakis, Nikolaos
    [J]. SENSORS, 2023, 23 (21)
  • [47] Toward Network-based DDoS Detection in Software-defined Networks
    Jevtic, Stefan
    Lotfalizadeh, Hamidreza
    Kim, Dongsoo S.
    [J]. PROCEEDINGS OF THE 12TH INTERNATIONAL CONFERENCE ON UBIQUITOUS INFORMATION MANAGEMENT AND COMMUNICATION (IMCOM 2018), 2018,
  • [49] SDNTruth: Innovative DDoS Detection Scheme for Software-Defined Networks (SDN)
    Linhares, Tiago
    Patel, Ahmed
    Barros, Ana Luiza
    Fernandez, Marcial
    [J]. JOURNAL OF NETWORK AND SYSTEMS MANAGEMENT, 2023, 31 (03)
  • [50] Machine learning assisted snort and zeek in detecting DDoS attacks in software-defined networking
    AbdulRaheem M.
    Oladipo I.D.
    Imoize A.L.
    Awotunde J.B.
    Lee C.-C.
    Balogun G.B.
    Adeoti J.O.
    [J]. International Journal of Information Technology, 2024, 16 (3) : 1627 - 1643