DDoS Attack Detection and Mitigation Using SDN: Methods, Practices, and Solutions

被引:0
|
作者
Narmeen Zakaria Bawany
Jawwad A. Shamsi
Khaled Salah
机构
[1] FAST-National University of Computer and Emerging Sciences,Systems Research Laboratory
[2] Khalifa University of Science,Electrical and Computer Engineering Department
[3] Technology and Research,undefined
关键词
Software-defined networking; SDN; DDoS attacks; OpenFlow; DDoS mitigation;
D O I
暂无
中图分类号
学科分类号
摘要
Distributed denial-of-service (DDoS) attacks have become a weapon of choice for hackers, cyber extortionists, and cyber terrorists. These attacks can swiftly incapacitate a victim, causing huge revenue losses. Despite the large number of traditional mitigation solutions that exists today, DDoS attacks continue to grow in frequency, volume, and severity. This calls for a new network paradigm to address the requirements of today’s challenging security threats. Software-defined networking (SDN) is an emerging network paradigm which has gained significant traction by many researchers to address the requirement of today’s data centers. Inspired by the capabilities of SDN, we present a comprehensive survey of existing SDN-based DDoS attack detection and mitigation solutions. We classify solutions based on DDoS attack detection techniques and identify requirements of an effective solution. Based on our findings, we propose a novel framework for detection and mitigation of DDoS attacks in a large-scale network which comprises a smart city built on SDN infrastructure. Our proposed framework is capable of meeting application-specific DDoS attack detection and mitigation requirements. The primary contribution of this paper is twofold. First, we provide an in-depth survey and discussion of SDN-based DDoS attack detection and mitigation mechanisms, and we classify them with respect to the detection techniques. Second, leveraging the characteristics of SDN for network security, we propose and present an SDN-based proactive DDoS Defense Framework (ProDefense). We show how this framework can be utilized to secure applications built for smart cities. Moreover, the paper highlights open research challenges, future research directions, and recommendations related to SDN-based DDoS detection and mitigation.
引用
收藏
页码:425 / 441
页数:16
相关论文
共 50 条
  • [41] Time-based DDoS Detection and Mitigation for SDN Controller
    Dharma, I. Gde N.
    Muthohar, M. Fiqri
    Prayuda, Alvin J. D.
    Priagung, K.
    Choi, Deokjai
    2015 17TH ASIA-PACIFIC NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM APNOMS, 2015, : 550 - 553
  • [42] A Research Review on SDN-Based DDOS Attack Detection
    Zhu, Weidong
    Yi, Xiujuan
    PROCEEDINGS OF THE 2017 INTERNATIONAL CONFERENCE ON MANAGEMENT SCIENCE AND MANAGEMENT INNOVATION (MSMI 2017), 2017, 31 : 145 - 149
  • [43] A New Framework for DDoS Attack Detection and Defense in SDN Environment
    Tan, Liang
    Pan, Yue
    Wu, Jing
    Zhou, Jianguo
    Jiang, Hao
    Deng, Yuchuan
    IEEE ACCESS, 2020, 8 : 161908 - 161919
  • [44] A CGAN-based DDoS Attack Detection Method in SDN
    Liu
    Luo
    Jiang
    Wang
    Li
    Jia
    IWCMC 2021: 2021 17TH INTERNATIONAL WIRELESS COMMUNICATIONS & MOBILE COMPUTING CONFERENCE (IWCMC), 2021, : 1030 - 1034
  • [45] Packet_In message based DDoS attack detection in SDN network using OpenFlow
    You, Xiang
    Feng, Yaokai
    Sakurai, Kouichi
    2017 FIFTH INTERNATIONAL SYMPOSIUM ON COMPUTING AND NETWORKING (CANDAR), 2017, : 522 - 528
  • [46] Detection of Control Layer DDoS Attack using Entropy metrics in SDN: An Empirical Investigation
    Sahoo, Kshira Sagar
    Sahoo, Bibhudatta
    Vankayala, Manikanta
    Dash, Ratnakar
    2017 NINTH INTERNATIONAL CONFERENCE ON ADVANCED COMPUTING (ICOAC), 2017, : 281 - 286
  • [47] Design a Robust DDoS Attack Detection and Mitigation Scheme in SDN-Edge-IoT by Leveraging Machine Learning
    Belachew, Habtamu Molla
    Beyene, Mulatu Yirga
    Desta, Abinet Bizuayehu
    Alemu, Behaylu Tadele
    Musa, Salahadin Seid
    Muhammed, Alemu Jorgi
    IEEE ACCESS, 2025, 13 : 10194 - 10214
  • [48] A DDoS attack detection and defense scheme using time-series analysis for SDN
    Fouladi, Ramin Fadaei
    Ermis, Orhan
    Anarim, Emin
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2020, 54 (54)
  • [49] Detection and mitigation of DDoS attack in cloud computing using machine learning algorithm
    Amjad, Aroosh
    Alyas, Tahir
    Farooq, Umer
    Tariq, Muhammad Arsian
    EAI ENDORSED TRANSACTIONS ON SCALABLE INFORMATION SYSTEMS, 2019, 6 (23) : 1 - 8
  • [50] Leveraging SDN for Collaborative DDoS Mitigation
    Hameed, Sufian
    Khan, Hassan Ahmed
    2017 INTERNATIONAL CONFERENCE ON NETWORKED SYSTEMS (NETSYS), 2017,