HTTPScout: A Machine Learning based Countermeasure for HTTP Flood Attacks in SDN

被引:0
|
作者
Reza Mohammadi
Chhagan Lal
Mauro Conti
机构
[1] Bu-Ali Sina University,
[2] TU Delft,undefined
[3] University of Padua,undefined
[4] Italy/TU Delft,undefined
来源
International Journal of Information Security | 2023年 / 22卷
关键词
SDN; DDoS; Flooding attack; Machine learning;
D O I
暂无
中图分类号
学科分类号
摘要
Nowadays, the number of Distributed Denial of Service (DDoS) attacks is growing rapidly. The aim of these type of attacks is to make the prominent and critical services unavailable for legitimate users. HTTP flooding is one of the most common DDoS attacks and because of its implementation in application layer, it is difficult to detect and prevent by the current defense mechanisms. This attack not only makes the web servers unavailable, but consumes the computational resources of the network equipment and congests communication links. Recently, the advent of Software Defined Networking (SDN) paradigm has enabled the network providers to detect and mitigate application layer DDoS attacks such as HTTP flooding. In this paper, we propose a defense mechanism named HTTPScout which leverages the benefits of SDN together with Machine Learning (ML) techniques to detect and mitigate HTTP flooding attack. HTTPScout is implemented as a security module in RYU controller and monitors the behavior of HTTP traffic flows. Upon detecting a malicious flow, it blocks the source of the attack at the edge switch and preserves the network resources from the adversarial effects of the attack. Simulation results confirm that HTTPScout brings a significant improvement of 64% in bandwidth consumption and 80% in the number of forwarding rules compared to normal SDN.
引用
收藏
页码:367 / 379
页数:12
相关论文
共 50 条
  • [21] A Countermeasure Method Using Poisonous Data Against Poisoning Attacks on IoT Machine Learning
    Chiba, Tomoki
    Sei, Yuichi
    Tahara, Yasuyuki
    Ohsuga, Akihiko
    INTERNATIONAL JOURNAL OF SEMANTIC COMPUTING, 2021, 15 (02) : 215 - 240
  • [22] Deep-Learning Based Injection Attacks Detection Method for HTTP
    Zhao, Chunhui
    Si, Shuaijie
    Tu, Tengfei
    Shi, Yijie
    Qin, Sujuan
    MATHEMATICS, 2022, 10 (16)
  • [23] A Cost-Effective Shuffling-Based Defense against HTTP DDoS Attacks with SDN/NFV
    Lin, Yi-Hui
    Kuo, Jian-Jhih
    Yang, De-Nian
    Chen, Wen-Tsuen
    2017 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2017,
  • [24] Q-MIND: Defeating Stealthy DoS Attacks in SDN with a Machine-learning based Defense Framework
    Phan, Trung V.
    Gias, T. M. Rayhan
    Islam, Syed Tasnimul
    Truong Thu Huong
    Nguyen Huu Thanh
    Bauschert, Thomas
    2019 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2019,
  • [25] To Detect the Distributed Denial -of-Service Attacks in SDN using Machine Learning Algorithms
    Banerjee, Shruti
    Chakraborty, Partha Sarathi
    2021 IEEE INTERNATIONAL CONFERENCE ON COMPUTING, COMMUNICATION, AND INTELLIGENT SYSTEMS (ICCCIS), 2021, : 966 - 971
  • [26] A Comparative Study for SDN Security Based on Machine Learning
    Alheeti K.M.A.
    Alzahrani A.
    Alamri M.
    Kareem A.K.
    Al Dosary D.
    International Journal of Interactive Mobile Technologies, 2023, 17 (11) : 131 - 140
  • [27] Machine Learning based QoE Prediction in SDN networks
    Abar, Tasnim
    Ben Letaifa, Asma
    El Asmi, Sadok
    2017 13TH INTERNATIONAL WIRELESS COMMUNICATIONS AND MOBILE COMPUTING CONFERENCE (IWCMC), 2017, : 1395 - 1400
  • [28] A Handover Assistance Algorithm Based on SDN and Machine Learning
    Yang, Zongchang
    Liu, Xiantao
    Wu, Mengting
    Huang, Wei
    2022 IEEE International Conference on Artificial Intelligence and Computer Applications, ICAICA 2022, 2022, : 208 - 212
  • [29] Adversarial Attacks on SDN-Based Deep Learning IDS System
    Huang, Chi-Hsuan
    Lee, Tsung-Han
    Chang, Lin-Huang
    Lin, Jhih-Ren
    Horng, Gwoboa
    MOBILE AND WIRELESS TECHNOLOGY 2018, ICMWT 2018, 2019, 513 : 181 - 191
  • [30] User behavior analytics-based classification of application layer HTTP-GET flood attacks
    Singh, Karanpreet
    Singh, Paramvir
    Kumar, Krishan
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2018, 112 : 97 - 114