HTTPScout: A Machine Learning based Countermeasure for HTTP Flood Attacks in SDN

被引:0
|
作者
Reza Mohammadi
Chhagan Lal
Mauro Conti
机构
[1] Bu-Ali Sina University,
[2] TU Delft,undefined
[3] University of Padua,undefined
[4] Italy/TU Delft,undefined
来源
International Journal of Information Security | 2023年 / 22卷
关键词
SDN; DDoS; Flooding attack; Machine learning;
D O I
暂无
中图分类号
学科分类号
摘要
Nowadays, the number of Distributed Denial of Service (DDoS) attacks is growing rapidly. The aim of these type of attacks is to make the prominent and critical services unavailable for legitimate users. HTTP flooding is one of the most common DDoS attacks and because of its implementation in application layer, it is difficult to detect and prevent by the current defense mechanisms. This attack not only makes the web servers unavailable, but consumes the computational resources of the network equipment and congests communication links. Recently, the advent of Software Defined Networking (SDN) paradigm has enabled the network providers to detect and mitigate application layer DDoS attacks such as HTTP flooding. In this paper, we propose a defense mechanism named HTTPScout which leverages the benefits of SDN together with Machine Learning (ML) techniques to detect and mitigate HTTP flooding attack. HTTPScout is implemented as a security module in RYU controller and monitors the behavior of HTTP traffic flows. Upon detecting a malicious flow, it blocks the source of the attack at the edge switch and preserves the network resources from the adversarial effects of the attack. Simulation results confirm that HTTPScout brings a significant improvement of 64% in bandwidth consumption and 80% in the number of forwarding rules compared to normal SDN.
引用
收藏
页码:367 / 379
页数:12
相关论文
共 50 条
  • [31] An Efficient Method for Online Detection of DRDoS Attacks on UDP-Based Services in SDN Using Machine Learning Algorithms
    Kohnehshahri, Mitra Akbari
    Mohammadi, Reza
    Abdoli, Hatam
    Nassiri, Mohammad
    MOBILE INFORMATION SYSTEMS, 2022, 2022
  • [32] A Flexible SDN-Based Architecture for Identifying and Mitigating Low-Rate DDoS Attacks Using Machine Learning
    Arturo Perez-Diaz, Jesus
    Amezcua Valdovinos, Ismael
    Choo, Kim-Kwang Raymond
    Zhu, Dakai
    IEEE ACCESS, 2020, 8 (08): : 155859 - 155872
  • [33] ORL-SDN: Online Reinforcement Learning for SDN-Enabled HTTP Adaptive Streaming
    Bentaleb, Abdelhak
    Begen, Ali C.
    Zimmermann, Roger
    ACM TRANSACTIONS ON MULTIMEDIA COMPUTING COMMUNICATIONS AND APPLICATIONS, 2018, 14 (03)
  • [34] A Protection System Against HTTP Flood Attacks Using Software Defined Networking
    Diego S. M. Gonçalves
    Rodrigo S. Couto
    Marcelo G. Rubinstein
    Journal of Network and Systems Management, 2023, 31
  • [35] A Protection System Against HTTP Flood Attacks Using Software Defined Networking
    Goncalves, Diego S. M.
    Couto, Rodrigo S.
    Rubinstein, Marcelo G.
    JOURNAL OF NETWORK AND SYSTEMS MANAGEMENT, 2023, 31 (01)
  • [36] Fuzzy protection method for flood attacks in Software Defined Networking (SDN)
    Zahedi, Mohammad Hadi (mhadi_zahedi@yahoo.com), 2018, Forum-Editrice Universitaria Udinese SRL
  • [37] FUZZY PROTECTION METHOD FOR FLOOD ATTACKS IN SOFTWARE DEFINED NETWORKING (SDN)
    Zahedi, Mohammad Hadi
    Rezaee, Abbas Ali
    Dehghan, Zeinab
    ITALIAN JOURNAL OF PURE AND APPLIED MATHEMATICS, 2018, (40): : 772 - 789
  • [38] The Research of Electronic Countermeasure Intelligence Correlation Analysis Based on Machine Learning
    Shi Ziyan
    Zhao Guolin
    Hu Qiaolin
    2018 5TH INTERNATIONAL CONFERENCE ON SYSTEMS AND INFORMATICS (ICSAI), 2018, : 389 - 394
  • [39] Machine Learning Based Video Coding Enhancements for HTTP Adaptive Streaming
    Cetinkaya, Ekrem
    MMSYS '21: PROCEEDINGS OF THE 2021 MULTIMEDIA SYSTEMS CONFERENCE, 2021, : 418 - 422
  • [40] HTTP header based phishing attack detection using machine learning
    Shukla, Sanjeev
    Misra, Manoj
    Varshney, Gaurav
    TRANSACTIONS ON EMERGING TELECOMMUNICATIONS TECHNOLOGIES, 2024, 35 (01)