Detection and Analysis of TCP-SYN DDoS Attack in Software-Defined Networking

被引:0
|
作者
Rochak Swami
Mayank Dave
Virender Ranga
机构
[1] National Institute of Technology,Department of Computer Engineering
来源
关键词
SDN; DDoS; IDS; Machine learning;
D O I
暂无
中图分类号
学科分类号
摘要
Software-defined networking (SDN) is an advanced networking technology that yields flexibility with cost-efficiency as per the business requirements. SDN breaks the vertical integration of control and data plane and promotes centralized network management. SDN allows data intensive applications to work more efficiently by making the network dynamically configurable. With the growing development of SDN technology, the issue of security becomes critical because of its architectural characteristics. Currently, Distributed denial of service (DDoS) is one of the most powerful attacks that cause the services to be unavailable for normal users. DDoS seeks to consume the resources of the SDN controller with the intention to slow down working of the network. In this paper, a detailed analysis of the effect of spoofed and non-spoofed TCP-SYN flooding attacks on the controller resources in SDN is presented. We also suggest a machine learning based intrusion detection system. Five different classification models belong to a variety of families are used to classify the traffic, and evaluated using different performance indicators. Cross-validation technique is used to validate the classification models. This work enables better features to be extracted and classify the traffic efficiently. The experimental results reveal significantly good performance with all the considered classification models.
引用
收藏
页码:2295 / 2317
页数:22
相关论文
共 50 条
  • [1] Detection and Analysis of TCP-SYN DDoS Attack in Software-Defined Networking
    Swami, Rochak
    Dave, Mayank
    Ranga, Virender
    [J]. WIRELESS PERSONAL COMMUNICATIONS, 2021, 118 (04) : 2295 - 2317
  • [2] FADM: DDoS Flooding Attack Detection and Mitigation System in Software-Defined Networking
    Hu, Dingwen
    Hong, Peilin
    Chen, Yixin
    [J]. GLOBECOM 2017 - 2017 IEEE GLOBAL COMMUNICATIONS CONFERENCE, 2017,
  • [3] Flood Control: TCP-SYN Flood Detection for Software-Defined Networks using OpenFlow Port Statistics
    Das, Tapadhir
    Abu Hamdan, Osama
    Sengupta, Shamik
    Arslan, Engin
    [J]. 2022 IEEE INTERNATIONAL CONFERENCE ON CYBER SECURITY AND RESILIENCE (IEEE CSR), 2022, : 1 - 8
  • [4] HTTP DDoS flooding attack mitigation in software-defined networking
    Park, Sungho
    Kim, Youngjun
    Choi, Hyungoo
    Kyung, Yeunwoong
    Park, Jinwoo
    [J]. IEICE Transactions on Information and Systems, 2021, E104D (09) : 1496 - 1499
  • [5] HTTP DDoS Flooding Attack Mitigation in Software-Defined Networking
    Park, Sungho
    Kim, Youngjun
    Choi, Hyungoo
    Kyung, Yeunwoong
    Park, Jinwoo
    [J]. IEICE TRANSACTIONS ON INFORMATION AND SYSTEMS, 2021, E104D (09): : 1496 - 1499
  • [6] Towards DDoS detection mechanisms in Software-Defined Networking
    Cui, Yunhe
    Qian, Qing
    Guo, Chun
    Shen, Guowei
    Tian, Youliang
    Xing, Huanlai
    Yan, Lianshan
    [J]. JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2021, 190
  • [7] Automated DDOS attack detection in software defined networking
    Ahuja, Nisha
    Singal, Gaurav
    Mukhopadhyay, Debajyoti
    Kumar, Neeraj
    [J]. JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2021, 187 (187)
  • [8] Machine Learning Approach Equipped with Neighbourhood Component Analysis for DDoS Attack Detection in Software-Defined Networking
    Tonkal, Ozgur
    Polat, Huseyin
    Basaran, Erdal
    Comert, Zafer
    Kocaoglu, Ramazan
    [J]. ELECTRONICS, 2021, 10 (11)
  • [9] Overview of DDoS Attack Detection in Software-Defined Networks
    Wang, Heyu
    Li, Yixuan
    [J]. IEEE ACCESS, 2024, 12 : 38351 - 38381
  • [10] DDoS attack protection in the era of cloud computing and Software-Defined Networking
    Wang, Bing
    Zheng, Yao
    Lou, Wenjing
    Hou, Y. Thomas
    [J]. COMPUTER NETWORKS, 2015, 81 : 308 - 319