Detecting and Preventing DDoS Attacks in SDN-Based Data Center Networks

被引:3
|
作者
Lin, Po-Ching [1 ]
Hsu, Yu-Ting [1 ]
Hwang, Ren-Hung [1 ]
机构
[1] Natl Chung Cheng Univ, Dept Comp Sci & Informat Engn, Chiayi, Taiwan
来源
关键词
DDoS; SDN; NFV; Virtual scrubbing function; Traffic redirection;
D O I
10.1007/978-3-319-68542-7_5
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Distributed denial-of-service (DDoS) attacks are deemed a serious threat to Internet services. A common solution to mitigate the attacks is to redirect traffic to scrubbing centers (SCs) for traffic classification and DDoS filtering. However, the capacity and locations of SCs should be pre-determined, and traffic redirection to SCs also give rise to extra network footprint and long latency. In this work, we present a solution based on network function virtualization (NFV) to launch scrubbing functions on demand and software-defined networking (SDN) to redirect traffic to these functions. We propose a lightweight probing strategy to identify anomalous traffic and the victim, and allocate virtual scrubbing functions close to the victim to minimize network footprint and network latency. We simulate a proof-of-concept design in Mininet to demonstrate its operation. The evaluation shows 96.6% of DDoS packets can be mitigated with the response time of one second.
引用
收藏
页码:50 / 61
页数:12
相关论文
共 50 条
  • [1] Detecting host location attacks in SDN-based networks
    Sen Baidya, Sonali
    Hewett, Rattikorn
    [J]. 2020 29TH WIRELESS AND OPTICAL COMMUNICATIONS CONFERENCE (WOCC), 2020, : 80 - 85
  • [2] Mitigating DDoS Attacks in SDN-Based IoT Networks Leveraging Secure Control and Data Plane Algorithm
    Wang, Song
    Gomez, Karina
    Sithamparanathan, Kandeepan
    Asghar, Muhammad Rizwan
    Russello, Giovanni
    Zanna, Paul
    [J]. APPLIED SCIENCES-BASEL, 2021, 11 (03): : 1 - 27
  • [3] An SDN-based Decision Tree Detection (DTD) Model for Detecting DDoS Attacks in Cloud Environment
    Praba, J. Jeba
    Sridaran, R.
    [J]. INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2022, 13 (07) : 54 - 64
  • [4] A Management Model for SDN-based Data Center Networks
    Xu, Yifei
    Yan, Yue
    Dai, Zhuyun
    Wang, Xiaolin
    [J]. 2014 IEEE CONFERENCE ON COMPUTER COMMUNICATIONS WORKSHOPS (INFOCOM WKSHPS), 2014, : 113 - +
  • [5] Multipath Routing in SDN-based Data Center Networks
    Lei, Yi-Chih
    Wang, Kuochen
    Hsu, Yi-Huai
    [J]. 2015 EUROPEAN CONFERENCE ON NETWORKS AND COMMUNICATIONS (EUCNC), 2015, : 365 - 369
  • [6] SDN-Based ECMP Algorithm for Data Center Networks
    Zhang, Hailong
    Guo, Xiao
    Yan, Jinyao
    Liu, Bo
    Shuai, Qianjun
    [J]. 2014 IEEE COMPUTING, COMMUNICATIONS AND IT APPLICATIONS CONFERENCE (COMCOMAP), 2014, : 13 - 18
  • [7] SDN-based detection and mitigation of DDoS attacks on smart homes
    Garba, Usman Haruna
    Toosi, Adel N.
    Pasha, Muhammad Fermi
    Khan, Suleman
    [J]. COMPUTER COMMUNICATIONS, 2024, 221 : 29 - 41
  • [8] A DDoS attacks traceback scheme for SDN-based smart city
    Chen, Wen
    Xiao, Suchao
    Liu, Leijie
    Jiang, Xueqin
    Tang, Zhangbin
    [J]. COMPUTERS & ELECTRICAL ENGINEERING, 2020, 81
  • [9] An SDN-based Approach For Defending Against Reflective DDoS Attacks
    Lukaseder, Thomas
    StOlzle, Kevin
    Kleber, Stephan
    Erb, Benjamin
    Kargl, Frank
    [J]. PROCEEDINGS OF THE 2018 IEEE 43RD CONFERENCE ON LOCAL COMPUTER NETWORKS (LCN), 2018, : 299 - 302
  • [10] Defending SDN-based IoT Networks Against DDoS Attacks Using Markov Decision Process
    Zheng, Jianjun
    Namin, Akbar Siami
    [J]. 2018 IEEE INTERNATIONAL CONFERENCE ON BIG DATA (BIG DATA), 2018, : 4589 - 4592