Defending Blind DDoS Attack on SDN Based on Moving Target Defense

被引:11
|
作者
Ma, Duohe [1 ,2 ]
Xu, Zhen [1 ]
Lin, Dongdai [1 ]
机构
[1] Chinese Acad Sci, Inst Informat Engn, State Key Lab Informat Secur, Beijing, Peoples R China
[2] Univ Chinese Acad Sci, Beijing, Peoples R China
关键词
Blind DDoS attack; Software defined networking; Moving target defense;
D O I
10.1007/978-3-319-23829-6_32
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Software Defined Networking (SDN) provides a new network solution by decoupling control plane and data plane from the closed and proprietary implementations of traditional network devices. With its promisingly advanced architecture, SDN represents the future development trend of network. In its typical structure, collaborative interaction between one controller and multiple switches forms a centralized network topology. As playing a key role in this network architecture, the controller in SDN is very vulnerable to single point of failure. What is worse, the emergence of Blind DDoS attack against SDN's special structure increases its risks. To address this challenge, we introduce a Moving Target Defense(MTD) system to defend Blind DDoS attack. The approach adopts a multi-controller pool to solve the saturation problem, and it can dynamically shift controllers connecting to switches according to the density of flood flow. By randomly delaying the scanning packets and filtering the flood with route-map, this MTD system can effectively resist the Blind DDoS attack and protect the availability and reliability of SDN.
引用
收藏
页码:463 / 480
页数:18
相关论文
共 50 条
  • [21] SDN-based IP Shuffling Moving Target Defense with Multiple SDN Controllers
    Narantuya, Jargalsaikhan
    Yoon, Seunghyun
    Lim, Hyuk
    Cho, Jin-Hee
    Kim, Dong Seong
    Moore, Terrence J.
    Nelson, Frederica F.
    [J]. 2019 49TH ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS - SUPPLEMENTAL VOL (DSN-S), 2019, : 15 - 16
  • [22] Cross-Plane DDoS Attack Defense Architecture Based on Flow Table Features in SDN
    Yue, Meng
    Yan, Qingxin
    Zheng, Han
    Wu, Zhijun
    [J]. SECURITY AND COMMUNICATION NETWORKS, 2022, 2022
  • [23] TDDAD: Time-Based Detection and Defense Scheme Against DDoS Attack on SDN Controller
    Cui, Jie
    He, Jiantao
    Xu, Yan
    Zhong, Hong
    [J]. INFORMATION SECURITY AND PRIVACY, 2018, 10946 : 649 - 665
  • [24] Cross-Plane DDoS Attack Defense Architecture Based on Flow Table Features in SDN
    Yue, Meng
    Yan, Qingxin
    Zheng, Han
    Wu, Zhijun
    [J]. Security and Communication Networks, 2022, 2022
  • [25] A DDoS attack defending scheme based on network processor
    Li Xinlei
    Zheng Kangfeng
    Yang Yixian
    [J]. 2009 WASE INTERNATIONAL CONFERENCE ON INFORMATION ENGINEERING, ICIE 2009, VOL II, 2009, : 238 - 241
  • [26] SDN-based solutions for Moving Target Defense network protection
    Kampanakis, Panos
    Perros, Harry
    Beyene, Tsegereda
    [J]. 2014 IEEE 15TH INTERNATIONAL SYMPOSIUM ON A WORLD OF WIRELESS, MOBILE AND MULTIMEDIA NETWORKS (WOWMOM), 2014,
  • [27] DEFENDING A MOVING TARGET AGAINST MISSILE OR TORPEDO ATTACK
    BOYELL, RL
    [J]. IEEE TRANSACTIONS ON AEROSPACE AND ELECTRONIC SYSTEMS, 1976, 12 (04) : 522 - 526
  • [28] Secure Multipath Mutation SMPM in Moving Target Defense Based on SDN
    Zkik, Karim
    Sebbar, Anass
    Baddi, Youssef
    Boulmalf, Mohammed
    [J]. 10TH INTERNATIONAL CONFERENCE ON AMBIENT SYSTEMS, NETWORKS AND TECHNOLOGIES (ANT 2019) / THE 2ND INTERNATIONAL CONFERENCE ON EMERGING DATA AND INDUSTRY 4.0 (EDI40 2019) / AFFILIATED WORKSHOPS, 2019, 151 : 977 - 984
  • [29] Countering crossfire DDoS attacks through moving target defense in SDN networks using OpenFlow traffic modification
    Hyder, Muhammad Faraz
    Fatima, Tasbiha
    Khan, Shariq Mahmood
    Arshad, Saadia
    [J]. TRANSACTIONS ON EMERGING TELECOMMUNICATIONS TECHNOLOGIES, 2023,
  • [30] Real-time DDoS Attack Defense System in SDN Using LSSOM
    Liu, Shijin
    Fukuda, Hiroaki
    Leger, Paul
    [J]. 2023 26TH CONFERENCE ON INNOVATION IN CLOUDS, INTERNET AND NETWORKS AND WORKSHOPS, ICIN, 2023,