DDoS Attack Detection and Mitigation Using SDN: Methods, Practices, and Solutions

被引:0
|
作者
Narmeen Zakaria Bawany
Jawwad A. Shamsi
Khaled Salah
机构
[1] FAST-National University of Computer and Emerging Sciences,Systems Research Laboratory
[2] Khalifa University of Science,Electrical and Computer Engineering Department
[3] Technology and Research,undefined
关键词
Software-defined networking; SDN; DDoS attacks; OpenFlow; DDoS mitigation;
D O I
暂无
中图分类号
学科分类号
摘要
Distributed denial-of-service (DDoS) attacks have become a weapon of choice for hackers, cyber extortionists, and cyber terrorists. These attacks can swiftly incapacitate a victim, causing huge revenue losses. Despite the large number of traditional mitigation solutions that exists today, DDoS attacks continue to grow in frequency, volume, and severity. This calls for a new network paradigm to address the requirements of today’s challenging security threats. Software-defined networking (SDN) is an emerging network paradigm which has gained significant traction by many researchers to address the requirement of today’s data centers. Inspired by the capabilities of SDN, we present a comprehensive survey of existing SDN-based DDoS attack detection and mitigation solutions. We classify solutions based on DDoS attack detection techniques and identify requirements of an effective solution. Based on our findings, we propose a novel framework for detection and mitigation of DDoS attacks in a large-scale network which comprises a smart city built on SDN infrastructure. Our proposed framework is capable of meeting application-specific DDoS attack detection and mitigation requirements. The primary contribution of this paper is twofold. First, we provide an in-depth survey and discussion of SDN-based DDoS attack detection and mitigation mechanisms, and we classify them with respect to the detection techniques. Second, leveraging the characteristics of SDN for network security, we propose and present an SDN-based proactive DDoS Defense Framework (ProDefense). We show how this framework can be utilized to secure applications built for smart cities. Moreover, the paper highlights open research challenges, future research directions, and recommendations related to SDN-based DDoS detection and mitigation.
引用
收藏
页码:425 / 441
页数:16
相关论文
共 50 条
  • [21] DDoS Attack Detection under SDN Context
    Xu, Yang
    Liu, Yong
    IEEE INFOCOM 2016 - THE 35TH ANNUAL IEEE INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATIONS, 2016,
  • [22] Review of Research on DDoS Attack Detection in SDN
    Zheng, Chengwei
    Wang, Haifeng
    Liu, Rui
    Computer Engineering and Applications, 2024, 60 (24) : 79 - 96
  • [23] Dynamic Attack Detection and Mitigation in IoT using SDN
    Bhunia, Suman Sankar
    Gurusamy, Mohan
    2017 27TH INTERNATIONAL TELECOMMUNICATION NETWORKS AND APPLICATIONS CONFERENCE (ITNAC), 2017, : 84 - 89
  • [24] DDoS Attack Detection and Classification Using Hybrid Model for Multicontroller SDN
    Gebremeskel, Tewelde Gebremedhin
    Gemeda, Ketema Adere
    Krishna, T. Gopi
    Ramulu, Perumalla Janaki
    Wireless Communications and Mobile Computing, 2023, 2023
  • [25] A DDoS Attack Mitigation Scheme in ISP Networks Using Machine Learning Based on SDN
    Nguyen Ngoc Tuan
    Pham Huy Hung
    Nguyen Danh Nghia
    Nguyen Van Tho
    Trung Van Phan
    Nguyen Huu Thanh
    ELECTRONICS, 2020, 9 (03)
  • [26] DDoS Attack Detection Method and Mitigation Using Pattern of the Flow
    Sanmorino, Ahmad
    Yazid, Setiadi
    2013 INTERNATIONAL CONFERENCE OF INFORMATION AND COMMUNICATION TECHNOLOGY (ICOICT), 2013, : 12 - 16
  • [27] An optimized weighted voting based ensemble model for DDoS attack detection and mitigation in SDN environment
    Maheshwari, Aastha
    Mehraj, Burhan
    Khan, Mohd Shaad
    Idrisi, Mohd Shaheem
    MICROPROCESSORS AND MICROSYSTEMS, 2022, 89
  • [28] DDoS in SDN: a review of open datasets, attack vectors and mitigation strategies
    Hill, Winston
    Acquaah, Yaa Takyiwaa
    Mason, Janelle
    Limbrick, Daniel
    Teixeira-Poit, Stephanie
    Coates, Carla
    Roy, Kaushik
    DISCOVER APPLIED SCIENCES, 2024, 6 (09)
  • [29] An Improved Method of DDoS Attack Detection for Controller of SDN
    Sun, Wenwen
    Li, Yi
    Guan, Shaopeng
    2019 IEEE 2ND INTERNATIONAL CONFERENCE ON COMPUTER AND COMMUNICATION ENGINEERING TECHNOLOGY (CCET), 2019, : 249 - 253
  • [30] An efficient DDoS attack detection mechanism in SDN environment
    Hnamte V.
    Hussain J.
    International Journal of Information Technology, 2023, 15 (5) : 2623 - 2636