HTTPScout: A Machine Learning based Countermeasure for HTTP Flood Attacks in SDN

被引:0
|
作者
Reza Mohammadi
Chhagan Lal
Mauro Conti
机构
[1] Bu-Ali Sina University,
[2] TU Delft,undefined
[3] University of Padua,undefined
[4] Italy/TU Delft,undefined
来源
International Journal of Information Security | 2023年 / 22卷
关键词
SDN; DDoS; Flooding attack; Machine learning;
D O I
暂无
中图分类号
学科分类号
摘要
Nowadays, the number of Distributed Denial of Service (DDoS) attacks is growing rapidly. The aim of these type of attacks is to make the prominent and critical services unavailable for legitimate users. HTTP flooding is one of the most common DDoS attacks and because of its implementation in application layer, it is difficult to detect and prevent by the current defense mechanisms. This attack not only makes the web servers unavailable, but consumes the computational resources of the network equipment and congests communication links. Recently, the advent of Software Defined Networking (SDN) paradigm has enabled the network providers to detect and mitigate application layer DDoS attacks such as HTTP flooding. In this paper, we propose a defense mechanism named HTTPScout which leverages the benefits of SDN together with Machine Learning (ML) techniques to detect and mitigate HTTP flooding attack. HTTPScout is implemented as a security module in RYU controller and monitors the behavior of HTTP traffic flows. Upon detecting a malicious flow, it blocks the source of the attack at the edge switch and preserves the network resources from the adversarial effects of the attack. Simulation results confirm that HTTPScout brings a significant improvement of 64% in bandwidth consumption and 80% in the number of forwarding rules compared to normal SDN.
引用
收藏
页码:367 / 379
页数:12
相关论文
共 50 条
  • [41] Machine Learning-Based Detection of Ransomware Using SDN
    Cusack, Greg
    Michel, Oliver
    Keller, Eric
    PROCEEDINGS OF THE 2018 ACM INTERNATIONAL WORKSHOP ON SECURITY IN SOFTWARE DEFINED NETWORKS & NETWORK FUNCTION VIRTUALIZATION (SDN-NFVSEC'18), 2018, : 1 - 6
  • [42] Machine Learning based Root Cause Analysis for SDN Network
    Tong, Van
    Souihi, Sami
    Hai Anh Tran
    Mellouk, Abdelhamid
    2021 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2021,
  • [43] The Research of Electronic Countermeasure Intelligence Correlation Analysis Based on Machine Learning
    Shi Ziyan
    Zhao Guolin
    Hu Qiaolin
    2018 11TH INTERNATIONAL CONGRESS ON IMAGE AND SIGNAL PROCESSING, BIOMEDICAL ENGINEERING AND INFORMATICS (CISP-BMEI 2018), 2018,
  • [44] Cooperative defense of DDoS attack based on machine learning in SDN
    Shang L.
    Chen M.
    Zhang L.
    Liu X.
    Shi T.
    Li B.
    Dianli Xitong Baohu yu Kongzhi/Power System Protection and Control, 2021, 49 (16): : 170 - 176
  • [45] Enhancing QoE based on Machine Learning and DASH in SDN networks
    Abar, Tasnim
    Ben Letaifa, Asma
    Elasmi, Sadok
    2018 32ND INTERNATIONAL CONFERENCE ON ADVANCED INFORMATION NETWORKING AND APPLICATIONS WORKSHOPS (WAINA), 2018, : 258 - 263
  • [46] QoE Oriented Cognitive Network Based on Machine Learning and SDN
    Wang, Lei
    Delaney, Declan T.
    2019 IEEE 11TH INTERNATIONAL CONFERENCE ON COMMUNICATION SOFTWARE AND NETWORKS (ICCSN 2019), 2019, : 678 - 681
  • [47] Research on "Inaccurate Learning" and its Countermeasure in Machine Learning
    Li, Guo-Chang
    ICNC 2008: FOURTH INTERNATIONAL CONFERENCE ON NATURAL COMPUTATION, VOL 1, PROCEEDINGS, 2008, : 227 - 231
  • [48] Adaptive Machine Learning Based Distributed Denial-of-Services Attacks Detection and Mitigation System for SDN-Enabled IoT
    Aslam, Muhammad
    Ye, Dengpan
    Tariq, Aqil
    Asad, Muhammad
    Hanif, Muhammad
    Ndzi, David
    Chelloug, Samia Allaoua
    Abd Elaziz, Mohamed
    Al-Qaness, Mohammed A. A.
    Jilani, Syeda Fizzah
    SENSORS, 2022, 22 (07)
  • [49] Detecting web-based attacks by machine learning
    Cao, Lai-Cheng
    PROCEEDINGS OF 2006 INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND CYBERNETICS, VOLS 1-7, 2006, : 2737 - 2742
  • [50] ONOS Flood Defender: A Real-Time Flood Attacks Detection and Mitigation System in SDN Networks
    Younis, Hussein
    Hamarsheh, Mohammad M. N.
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2025, 37 (4-5):