Software-Defined Networking (SDN) and Distributed Denial of Service (DDoS) Attacks in Cloud Computing Environments: A Survey, Some Research Issues, and Challenges

被引:509
|
作者
Yan, Qiao [1 ]
Yu, F. Richard [2 ]
Gong, Qingxiang [1 ]
Li, Jianqiang [1 ]
机构
[1] Shenzhen Univ, Coll Comp Sci & Software Engn, Shenzhen 518060, Peoples R China
[2] Carleton Univ, Dept Syst & Comp Engn, Ottawa, ON K1S 5B6, Canada
来源
基金
加拿大自然科学与工程研究理事会; 美国国家科学基金会;
关键词
Software-defined networking (SDN); distributed denial of service attacks (DDoS); cloud computing; ANOMALY DETECTION; ENERGY-EFFICIENT; VIRTUALIZATION; SECURITY; FLOW; PRIVACY; SCHEME;
D O I
10.1109/COMST.2015.2487361
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Distributed denial of service (DDoS) attacks in cloud computing environments are growing due to the essential characteristics of cloud computing. With recent advances in software-defined networking (SDN), SDN-based cloud brings us new chances to defeat DDoS attacks in cloud computing environments. Nevertheless, there is a contradictory relationship between SDN and DDoS attacks. On one hand, the capabilities of SDN, including software-based traffic analysis, centralized control, global view of the network, dynamic updating of forwarding rules, make it easier to detect and react to DDoS attacks. On the other hand, the security of SDN itself remains to be addressed, and potential DDoS vulnerabilities exist across SDN platforms. In this paper, we discuss the new trends and characteristics of DDoS attacks in cloud computing, and provide a comprehensive survey of defense mechanisms against DDoS attacks using SDN. In addition, we review the studies about launching DDoS attacks on SDN, as well as the methods against DDoS attacks in SDN. To the best of our knowledge, the contradictory relationship between SDN and DDoS attacks has not been well addressed in previous works. This work can help to understand how to make full use of SDN's advantages to defeat DDoS attacks in cloud computing environments and how to prevent SDN itself from becoming a victim of DDoS attacks, which are important for the smooth evolution of SDN-based cloud without the distraction of DDoS attacks.
引用
收藏
页码:602 / 622
页数:21
相关论文
共 50 条
  • [1] Distributed Denial of Service Attacks in Software-Defined Networking with Cloud Computing
    Yan, Qiao
    Yu, F. Richard
    [J]. IEEE COMMUNICATIONS MAGAZINE, 2015, 53 (04) : 52 - 59
  • [2] A Survey on Distributed Denial of Service (DDoS) Attacks in SDN and Cloud Computing Environments
    Dong, Shi
    Abbas, Khushnood
    Jain, Raj
    [J]. IEEE ACCESS, 2019, 7 : 80813 - 80828
  • [3] Distributed Denial of Service (DDoS) Attacks in Software-defined Networks (SDN)
    Chahal, Jasmeen Kaur
    Kaur, Puninder
    Sharma, Avinash
    [J]. 2021 5TH INTERNATIONAL CONFERENCE ON ELECTRICAL, ELECTRONICS, COMMUNICATION, COMPUTER TECHNOLOGIES AND OPTIMIZATION TECHNIQUES (ICEECCOT), 2021, : 291 - 295
  • [4] Real-Time Detection and Mitigation of Distributed Denial of Service (DDoS) Attacks in Software Defined Networking (SDN)
    Lawal, Babatunde Hafis
    At, Nuray
    [J]. 2018 26TH SIGNAL PROCESSING AND COMMUNICATIONS APPLICATIONS CONFERENCE (SIU), 2018,
  • [5] Distributed denial of service (DDoS) attack mitigation in software defined network (SDN)-based cloud computing environment
    Bhushan, Kriti
    Gupta, B. B.
    [J]. JOURNAL OF AMBIENT INTELLIGENCE AND HUMANIZED COMPUTING, 2019, 10 (05) : 1985 - 1997
  • [6] Distributed denial of service (DDoS) attack mitigation in software defined network (SDN)-based cloud computing environment
    Kriti Bhushan
    B. B. Gupta
    [J]. Journal of Ambient Intelligence and Humanized Computing, 2019, 10 : 1985 - 1997
  • [7] A Taxonomy of Software-Defined Networking (SDN)-Enabled Cloud Computing
    Son, Jungmin
    Buyya, Rajkumar
    [J]. ACM COMPUTING SURVEYS, 2018, 51 (03)
  • [8] DDoS attack protection in the era of cloud computing and Software-Defined Networking
    Wang, Bing
    Zheng, Yao
    Lou, Wenjing
    Hou, Y. Thomas
    [J]. COMPUTER NETWORKS, 2015, 81 : 308 - 319
  • [9] DDoS Attack Protection in the Era of Cloud Computing and Software-Defined Networking
    Wang, Bing
    Zheng, Yao
    Lou, Wenjing
    Hou, Y. Thomas
    [J]. 2014 IEEE 22ND INTERNATIONAL CONFERENCE ON NETWORK PROTOCOLS (ICNP), 2014, : 624 - 629
  • [10] Detection Techniques of Distributed Denial of Service Attacks on Software-Defined Networking Controller-A Review
    Aladaileh, Mohammad A.
    Anbar, Mohammed
    Hasbullah, Iznan H.
    Chong, Yung-Wey
    Sanjalawe, Yousef K.
    [J]. IEEE ACCESS, 2020, 8 : 143985 - 143995