Detection and Analysis of TCP-SYN DDoS Attack in Software-Defined Networking

被引:23
|
作者
Swami, Rochak [1 ]
Dave, Mayank [1 ]
Ranga, Virender [1 ]
机构
[1] Natl Inst Technol, Dept Comp Engn, Kurukshetra 136119, Haryana, India
关键词
SDN; DDoS; IDS; Machine learning; DETECTION SYSTEMS; SDN; CHALLENGES;
D O I
10.1007/s11277-021-08127-6
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
Software-defined networking (SDN) is an advanced networking technology that yields flexibility with cost-efficiency as per the business requirements. SDN breaks the vertical integration of control and data plane and promotes centralized network management. SDN allows data intensive applications to work more efficiently by making the network dynamically configurable. With the growing development of SDN technology, the issue of security becomes critical because of its architectural characteristics. Currently, Distributed denial of service (DDoS) is one of the most powerful attacks that cause the services to be unavailable for normal users. DDoS seeks to consume the resources of the SDN controller with the intention to slow down working of the network. In this paper, a detailed analysis of the effect of spoofed and non-spoofed TCP-SYN flooding attacks on the controller resources in SDN is presented. We also suggest a machine learning based intrusion detection system. Five different classification models belong to a variety of families are used to classify the traffic, and evaluated using different performance indicators. Cross-validation technique is used to validate the classification models. This work enables better features to be extracted and classify the traffic efficiently. The experimental results reveal significantly good performance with all the considered classification models.
引用
下载
收藏
页码:2295 / 2317
页数:23
相关论文
共 50 条
  • [31] Feature Selection and 1DCNN-based DDOS Detection in Software-Defined Networking
    Almi'ani, Noor
    Anbar, Mohammed
    Karuppayah, Shankar
    Sanjalawe, Yousef
    Alrababah, Hamza
    Abu Zwayed, Fadi
    Hasbullah, Iznan H.
    ENGINEERING LETTERS, 2024, 32 (07) : 1529 - 1544
  • [32] Improved Network Monitoring Using Software-Defined Networking for DDoS Detection and Mitigation Evaluation
    J. Ramprasath
    V. Seethalakshmi
    Wireless Personal Communications, 2021, 116 : 2743 - 2757
  • [33] Improved Network Monitoring Using Software-Defined Networking for DDoS Detection and Mitigation Evaluation
    Ramprasath, J.
    Seethalakshmi, V.
    WIRELESS PERSONAL COMMUNICATIONS, 2021, 116 (03) : 2743 - 2757
  • [34] Analyzing effective mitigation of DDoS attack with software defined networking
    Dayal, Neelam
    Srivastava, Shashank
    COMPUTERS & SECURITY, 2023, 130
  • [35] ATTAIN: An Attack Injection Framework for Software-Defined Networking
    Ujcich, Benjamin E.
    Thakore, Uttam
    Sanders, William H.
    2017 47TH ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS (DSN), 2017, : 567 - 578
  • [36] MIND: Message Classification Based Controller Scheduling Method for Resisting DDoS Attack in Software-Defined Networking
    Cui, Yunhe
    Qian, Qing
    2020 5TH INTERNATIONAL CONFERENCE ON COMPUTER AND COMMUNICATION SYSTEMS (ICCCS 2020), 2020, : 486 - 490
  • [37] Evaluation of TCP and UDP Traffic over Software-Defined Networking
    Naing, May Thae
    Khaing, Thiri Thitsar
    Maw, Aung Htein
    2019 INTERNATIONAL CONFERENCE ON ADVANCED INFORMATION TECHNOLOGIES (ICAIT), 2019, : 7 - 12
  • [38] Software-Defined Networking
    Kirkpatrick, Keith
    COMMUNICATIONS OF THE ACM, 2013, 56 (09) : 16 - 19
  • [39] Software-defined networking
    Greene, Kate
    Technology Review, 2009, 112 (02)
  • [40] Software-Defined Networking
    Zhili Sun
    Jiandong Li
    Kun Yang
    ZTE Communications, 2014, 12 (02) : 1 - 2