Collaborative detection and mitigation of DDoS in software-defined networks

被引:0
|
作者
Omer Elsier Tayfour
Muhammad Nadzir Marsono
机构
[1] Universiti Teknologi Malaysia,School of Electrical Engineering
来源
关键词
Software-defined network; Distributed denial-of-service; Redis simple message queue; Machine learning; Ensemble classifier;
D O I
暂无
中图分类号
学科分类号
摘要
This research presents the detection and mitigation of distributed denial of service (DDoS) in software defined networks (SDN). The proposed method consists of three modules: classifier module, mitigation module, and collaborative module. An ensemble classifier called V-NKDE is capable of detecting DDoS attacks accurately. The mitigation module blocks malicious traffics and purges entries of malicious traffic from the switch flow table. The collaborative module shares DDoS detection and mitigation rules among multiple SDN controllers using Redis Simple Message Queue mechanism. The proposed classifier performance validation on InSDN2020, CICIDS2017, NSL-KDD and UNSW-NB15 datasets. Furthermore we evaluated our proposed classifier in real traffic on an SDN simulation tested. The results show that the proposed method can detect DDoS attacks with high accuracy using an ensemble classifier, which performs better than single classifiers. More importantly, the false positive rate is greatly reduced, showing detection and mitigation of DDoS attacks across multi-controller domains with low controller overhead.
引用
收藏
页码:13166 / 13190
页数:24
相关论文
共 50 条
  • [1] Collaborative detection and mitigation of DDoS in software-defined networks
    Tayfour, Omer Elsier
    Marsono, Muhammad Nadzir
    [J]. JOURNAL OF SUPERCOMPUTING, 2021, 77 (11): : 13166 - 13190
  • [2] A comprehensive survey on DDoS detection, mitigation, and defense strategies in software-defined networks
    Jain, Ankit Kumar
    Shukla, Hariom
    Goel, Diksha
    [J]. CLUSTER COMPUTING-THE JOURNAL OF NETWORKS SOFTWARE TOOLS AND APPLICATIONS, 2024, 27 (09): : 13129 - 13164
  • [3] Overview of DDoS Attack Detection in Software-Defined Networks
    Wang, Heyu
    Li, Yixuan
    [J]. IEEE ACCESS, 2024, 12 : 38351 - 38381
  • [4] Mitigation and Detection of DDoS Attacks in Software Defined Networks
    Murtuza, Shariq
    Asawa, Krishna
    [J]. 2018 ELEVENTH INTERNATIONAL CONFERENCE ON CONTEMPORARY COMPUTING (IC3), 2018, : 389 - 391
  • [5] A DDoS Attack Detection and Mitigation With Software-Defined Internet of Things Framework
    Yin, Da
    Zhang, Lianming
    Yang, Kun
    [J]. IEEE ACCESS, 2018, 6 : 24694 - 24705
  • [6] Towards an Efficient DDoS Detection Scheme for Software-Defined Networks
    Lima, N. A. S.
    Fernandez, M. P.
    [J]. IEEE LATIN AMERICA TRANSACTIONS, 2018, 16 (08) : 2296 - 2301
  • [7] FADM: DDoS Flooding Attack Detection and Mitigation System in Software-Defined Networking
    Hu, Dingwen
    Hong, Peilin
    Chen, Yixin
    [J]. GLOBECOM 2017 - 2017 IEEE GLOBAL COMMUNICATIONS CONFERENCE, 2017,
  • [8] Detection and Mitigation of DDoS Attacks Using Conditional Entropy in Software-defined Networking
    Xuanyuan, Ming
    Ramsurrun, Visham
    Seeam, Amar
    [J]. 2019 11TH INTERNATIONAL CONFERENCE ON ADVANCED COMPUTING (ICOAC 2019), 2019, : 66 - 71
  • [9] Emerging DDoS attack detection and mitigation strategies in software-defined networks: Taxonomy, challenges and future directions
    Valdovinos, Ismael Amezcua
    Perez-Diaz, Jesus Arturo
    Choo, Kim-Kwang Raymond
    Botero, Juan Felipe
    [J]. JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2021, 187
  • [10] SDNTruth: Innovative DDoS Detection Scheme for Software-Defined Networks (SDN)
    Tiago Linhares
    Ahmed Patel
    Ana Luiza Barros
    Marcial Fernandez
    [J]. Journal of Network and Systems Management, 2023, 31