Defending Blind DDoS Attack on SDN Based on Moving Target Defense

被引:11
|
作者
Ma, Duohe [1 ,2 ]
Xu, Zhen [1 ]
Lin, Dongdai [1 ]
机构
[1] Chinese Acad Sci, Inst Informat Engn, State Key Lab Informat Secur, Beijing, Peoples R China
[2] Univ Chinese Acad Sci, Beijing, Peoples R China
关键词
Blind DDoS attack; Software defined networking; Moving target defense;
D O I
10.1007/978-3-319-23829-6_32
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Software Defined Networking (SDN) provides a new network solution by decoupling control plane and data plane from the closed and proprietary implementations of traditional network devices. With its promisingly advanced architecture, SDN represents the future development trend of network. In its typical structure, collaborative interaction between one controller and multiple switches forms a centralized network topology. As playing a key role in this network architecture, the controller in SDN is very vulnerable to single point of failure. What is worse, the emergence of Blind DDoS attack against SDN's special structure increases its risks. To address this challenge, we introduce a Moving Target Defense(MTD) system to defend Blind DDoS attack. The approach adopts a multi-controller pool to solve the saturation problem, and it can dynamically shift controllers connecting to switches according to the density of flood flow. By randomly delaying the scanning packets and filtering the flood with route-map, this MTD system can effectively resist the Blind DDoS attack and protect the availability and reliability of SDN.
引用
收藏
页码:463 / 480
页数:18
相关论文
共 50 条
  • [1] Mitigation of DDoS Attack Using Moving Target Defense in SDN
    Swami, Rochak
    Dave, Mayank
    Ranga, Virender
    [J]. WIRELESS PERSONAL COMMUNICATIONS, 2023, 131 (04) : 2429 - 2443
  • [2] Mitigation of DDoS Attack Using Moving Target Defense in SDN
    Rochak Swami
    Mayank Dave
    Virender Ranga
    [J]. Wireless Personal Communications, 2023, 131 : 2429 - 2443
  • [3] SDN/NFV-Based Moving Target DDoS Defense Mechanism
    Liu, Chien-Chang
    Huang, Bo-Sheng
    Tseng, Chia-Wei
    Yang, Yao-Tsung
    Chou, Li-Der
    [J]. RECENT TRENDS IN DATA SCIENCE AND SOFT COMPUTING, IRICT 2018, 2019, 843 : 548 - 556
  • [4] DDoS Attack Isolation using Moving Target Defense
    Department, Kansal
    Dave, Mayank
    [J]. 2017 IEEE INTERNATIONAL CONFERENCE ON COMPUTING, COMMUNICATION AND AUTOMATION (ICCCA), 2017, : 511 - 514
  • [5] Cooperative defense of DDoS attack based on machine learning in SDN
    Shang, Li
    Chen, Ming
    Zhang, Lei
    Liu, Xintong
    Shi, Tai
    Li, Baogang
    [J]. Dianli Xitong Baohu yu Kongzhi/Power System Protection and Control, 2021, 49 (16): : 170 - 176
  • [6] Research on moving target defense based on SDN
    Chen, Mingyong
    Wu, Weimin
    [J]. GREEN ENERGY AND SUSTAINABLE DEVELOPMENT I, 2017, 1864
  • [7] Multi-SDN Based Cooperation Scheme for DDoS Attack Defense
    He, Boren
    Zou, Futai
    Wu, Yue
    [J]. 2018 THIRD INTERNATIONAL CONFERENCE ON SECURITY OF SMART CITIES, INDUSTRIAL CONTROL SYSTEM AND COMMUNICATIONS (SSIC), 2018,
  • [8] A moving target DDoS defense mechanism
    Wang, Huangxin
    Jia, Quan
    Fleck, Dan
    Powell, Walter
    Li, Fei
    Stavrou, Angelos
    [J]. COMPUTER COMMUNICATIONS, 2014, 46 : 10 - 21
  • [9] DDoS Attack Identification and Defense using SDN based on Machine Learning Method
    Yang Lingfeng
    Zhao Hui
    [J]. 2018 15TH INTERNATIONAL SYMPOSIUM ON PERVASIVE SYSTEMS, ALGORITHMS AND NETWORKS (I-SPAN 2018), 2018, : 166 - 170
  • [10] DDoS attack detection and defense based on hybrid deep learning model in SDN
    SDN下基于深度学习混合模型的DDoS攻击检测与防御
    [J]. 2018, Editorial Board of Journal on Communications (39):