Software-Defined Networking (SDN) and Distributed Denial of Service (DDoS) Attacks in Cloud Computing Environments: A Survey, Some Research Issues, and Challenges

被引:509
|
作者
Yan, Qiao [1 ]
Yu, F. Richard [2 ]
Gong, Qingxiang [1 ]
Li, Jianqiang [1 ]
机构
[1] Shenzhen Univ, Coll Comp Sci & Software Engn, Shenzhen 518060, Peoples R China
[2] Carleton Univ, Dept Syst & Comp Engn, Ottawa, ON K1S 5B6, Canada
来源
基金
加拿大自然科学与工程研究理事会; 美国国家科学基金会;
关键词
Software-defined networking (SDN); distributed denial of service attacks (DDoS); cloud computing; ANOMALY DETECTION; ENERGY-EFFICIENT; VIRTUALIZATION; SECURITY; FLOW; PRIVACY; SCHEME;
D O I
10.1109/COMST.2015.2487361
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Distributed denial of service (DDoS) attacks in cloud computing environments are growing due to the essential characteristics of cloud computing. With recent advances in software-defined networking (SDN), SDN-based cloud brings us new chances to defeat DDoS attacks in cloud computing environments. Nevertheless, there is a contradictory relationship between SDN and DDoS attacks. On one hand, the capabilities of SDN, including software-based traffic analysis, centralized control, global view of the network, dynamic updating of forwarding rules, make it easier to detect and react to DDoS attacks. On the other hand, the security of SDN itself remains to be addressed, and potential DDoS vulnerabilities exist across SDN platforms. In this paper, we discuss the new trends and characteristics of DDoS attacks in cloud computing, and provide a comprehensive survey of defense mechanisms against DDoS attacks using SDN. In addition, we review the studies about launching DDoS attacks on SDN, as well as the methods against DDoS attacks in SDN. To the best of our knowledge, the contradictory relationship between SDN and DDoS attacks has not been well addressed in previous works. This work can help to understand how to make full use of SDN's advantages to defeat DDoS attacks in cloud computing environments and how to prevent SDN itself from becoming a victim of DDoS attacks, which are important for the smooth evolution of SDN-based cloud without the distraction of DDoS attacks.
引用
收藏
页码:602 / 622
页数:21
相关论文
共 50 条
  • [31] A Comprehensive Survey of Distributed Denial of Service Detection and Mitigation Technologies in Software-Defined Network
    Su, Yinghao
    Xiong, Dapeng
    Qian, Kechang
    Wang, Yu
    [J]. ELECTRONICS, 2024, 13 (04)
  • [32] A Novel Distributed Denial-of-Service Attack Detection Scheme for Software Defined Networking Environments
    Wu, Di
    Li, Jie
    Das, Sajal K.
    Wu, Jinsong
    Ji, Yusheng
    Li, Zhetao
    [J]. 2018 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2018,
  • [33] Distributed Denial-of-Service (DDoS) Attacks and Defense Mechanisms in Various Web-Enabled Computing Platforms: Issues, Challenges, and Future Research Directions
    Singh, Anshuman
    Gupta, Brij B.
    [J]. INTERNATIONAL JOURNAL ON SEMANTIC WEB AND INFORMATION SYSTEMS, 2022, 18 (01)
  • [34] A survey of Blockchain technologies applied to software-defined networking: Research challenges and solutions
    Hai Nam Nguyen
    Hai Anh Tran
    Fowler, Scott
    Souihi, Sami
    [J]. IET WIRELESS SENSOR SYSTEMS, 2021, 11 (06) : 233 - 247
  • [35] DoS and DDoS attacks in Software Defined Networks: A survey of existing solutions and research challenges
    Eliyan, Lubna Fayez
    Di Pietro, Roberto
    [J]. FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2021, 122 (122): : 149 - 171
  • [36] Mitigating TCP Incast Issue in Cloud Data Centres using Software-Defined Networking (SDN): A Survey
    Shah, Zawar
    [J]. KSII TRANSACTIONS ON INTERNET AND INFORMATION SYSTEMS, 2018, 12 (11): : 5179 - 5202
  • [37] Whack-a-Mole: Software-defined Networking driven Multi-level DDoS defense for Cloud environments
    Nguyen, Minh
    Pal, Amitangshu
    Debroy, Saptarshi
    [J]. PROCEEDINGS OF THE 2018 IEEE 43RD CONFERENCE ON LOCAL COMPUTER NETWORKS (LCN), 2018, : 493 - 501
  • [38] Investigating high traffic rate distributed denial of service attacks detection mechanisms in Software-Defined Networks
    Sejaphala, Lanka Chris
    Velempini, Mthulisi
    [J]. 2018 CONFERENCE ON INFORMATION COMMUNICATIONS TECHNOLOGY AND SOCIETY (ICTAS), 2018,
  • [39] Development and research of models of organization distributed cloud computing based on the software-defined infrastructure
    Bolodurina, I.
    Parfenov, D.
    [J]. XII INTERNATIONAL SYMPOSIUM INTELLIGENT SYSTEMS 2016, (INTELS 2016), 2017, 103 : 569 - 576
  • [40] Entropy based mitigation of Distributed-Denial-of-Service (DDoS) attack on Control Plane in Software-Defined-Network (SDN)
    Yadav, Sanjay Kumar
    Suguna, P.
    Velusamy, R. Leela
    [J]. 2019 10TH INTERNATIONAL CONFERENCE ON COMPUTING, COMMUNICATION AND NETWORKING TECHNOLOGIES (ICCCNT), 2019,