Software-Defined Networking (SDN) and Distributed Denial of Service (DDoS) Attacks in Cloud Computing Environments: A Survey, Some Research Issues, and Challenges

被引:509
|
作者
Yan, Qiao [1 ]
Yu, F. Richard [2 ]
Gong, Qingxiang [1 ]
Li, Jianqiang [1 ]
机构
[1] Shenzhen Univ, Coll Comp Sci & Software Engn, Shenzhen 518060, Peoples R China
[2] Carleton Univ, Dept Syst & Comp Engn, Ottawa, ON K1S 5B6, Canada
来源
基金
加拿大自然科学与工程研究理事会; 美国国家科学基金会;
关键词
Software-defined networking (SDN); distributed denial of service attacks (DDoS); cloud computing; ANOMALY DETECTION; ENERGY-EFFICIENT; VIRTUALIZATION; SECURITY; FLOW; PRIVACY; SCHEME;
D O I
10.1109/COMST.2015.2487361
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Distributed denial of service (DDoS) attacks in cloud computing environments are growing due to the essential characteristics of cloud computing. With recent advances in software-defined networking (SDN), SDN-based cloud brings us new chances to defeat DDoS attacks in cloud computing environments. Nevertheless, there is a contradictory relationship between SDN and DDoS attacks. On one hand, the capabilities of SDN, including software-based traffic analysis, centralized control, global view of the network, dynamic updating of forwarding rules, make it easier to detect and react to DDoS attacks. On the other hand, the security of SDN itself remains to be addressed, and potential DDoS vulnerabilities exist across SDN platforms. In this paper, we discuss the new trends and characteristics of DDoS attacks in cloud computing, and provide a comprehensive survey of defense mechanisms against DDoS attacks using SDN. In addition, we review the studies about launching DDoS attacks on SDN, as well as the methods against DDoS attacks in SDN. To the best of our knowledge, the contradictory relationship between SDN and DDoS attacks has not been well addressed in previous works. This work can help to understand how to make full use of SDN's advantages to defeat DDoS attacks in cloud computing environments and how to prevent SDN itself from becoming a victim of DDoS attacks, which are important for the smooth evolution of SDN-based cloud without the distraction of DDoS attacks.
引用
收藏
页码:602 / 622
页数:21
相关论文
共 50 条
  • [41] A robust tuned classifier-based distributed denial of service attacks detection for quality of service enhancement in software-defined network
    Kaur, Gaganjot
    Gupta, Prinima
    [J]. JOURNAL OF INTELLIGENT & FUZZY SYSTEMS, 2022, 43 (03) : 2693 - 2710
  • [42] Research on Detection and Defense Methods for Software-Defined Network Architecture after Hybrid Attack by Distributed Denial of Service
    Xiao, Hongfei
    Xiang, Tao
    Tang, Shiqi
    [J]. IEEJ TRANSACTIONS ON ELECTRICAL AND ELECTRONIC ENGINEERING, 2024, 19 (06) : 1001 - 1006
  • [43] Integration of Networking, Caching, and Computing in Wireless Systems: A Survey, Some Research Issues, and Challenges
    Wang, Chenmeng
    He, Ying
    Yu, F. Richard
    Chen, Qianbin
    Tang, Lun
    [J]. IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2018, 20 (01): : 7 - 38
  • [44] A novel Distributed Denial of Service attack defense scheme for Software-Defined Networking using Packet-In message and frequency domain analysis
    Fouladi, Ramin Fadaei
    Karaçay, Leyli
    Gülen, Utku
    Soykan, Elif Ustundag
    [J]. Computers and Electrical Engineering, 2024, 120
  • [45] Implementing an intrusion detection and prevention system using software-defined networking: Defending against port-scanning and denial-of-service attacks
    Birkinshaw, Celyn
    Rouka, Elpida
    Vassilakis, Vassilios G.
    [J]. JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2019, 136 : 71 - 85
  • [46] Deep Neural Network (DNN) Solution for Real-time Detection of Distributed Denial of Service (DDoS) Attacks in Software Defined Networks (SDNs)
    Makuvaza A.
    Jat D.S.
    Gamundani A.M.
    [J]. SN Computer Science, 2021, 2 (2)
  • [47] A Review on Software-Defined Networking for Internet of Things Inclusive of Distributed Computing, Blockchain, and Mobile Network Technology: Basics, Trends, Challenges, and Future Research Potentials
    Shafiq, Shakila
    Rahman, Md. Sazzadur
    Shaon, Shamim Ahmed
    Mahmud, Imtiaz
    Hosen, A. S. M. Sanwar
    [J]. INTERNATIONAL JOURNAL OF DISTRIBUTED SENSOR NETWORKS, 2024, 2024
  • [48] Towards Crossfire Distributed Denial of Service Attack Protection Using Intent-Based Moving Target Defense Over Software-Defined Networking
    Hyder, Muhammad Faraz
    Fatima, Tasbiha
    [J]. IEEE ACCESS, 2021, 9 : 112792 - 112804
  • [49] Software-Defined-Networking-Based One-versus-Rest Strategy for Detecting and Mitigating Distributed Denial-of-Service Attacks in Smart Home Internet of Things Devices
    Karmous, Neder
    Aoueileyine, Mohamed Ould-Elhassen
    Abdelkader, Manel
    Romdhani, Lamia
    Youssef, Neji
    [J]. SENSORS, 2024, 24 (15)
  • [50] Intelligent software defined networking: Long short term memory-graded rated unit enabled block-attack model to tackle distributed denial of service attacks
    Jagtap, Monica Murlidhar
    Saravanan, Renuka Devi
    [J]. TRANSACTIONS ON EMERGING TELECOMMUNICATIONS TECHNOLOGIES, 2022, 33 (11):