SDN/NFV-based framework for autonomous defense against slow-rate DDoS attacks by using reinforcement learning

被引:10
|
作者
Yungaicela-Naula, Noe M. [1 ]
Vargas-Rosales, Cesar [1 ]
Perez-Diaz, Jesus A. [1 ]
机构
[1] Tecnol Monterrey, Sch Engn & Sci, Monterrey 64849, Nuevo Leon, Mexico
关键词
Network function virtualization (NFV); Moving target defense (MTD); Reinforcement learning (RL); Slow-rate DDoS; Software defined networking (SDN); Zero touch networks and service; management (ZSM); MOVING TARGET DEFENSE; SDN;
D O I
10.1016/j.future.2023.08.007
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
The unforeseen and skyrocketed shift in the number of connections to the Internet during the last years has created vast and critical vulnerabilities in networks that cybercriminals have quickly seized to launch high-volume DDoS attacks. Existing tools, such as advanced firewalls or intrusion prevention systems (IPS), cannot handle such an elevated volume of attacks because these solutions are dependent on humans. Therefore, adaptation of the current network security solutions to automated ones is more significant than ever to foster the development of the zero-touch networks and service management (ZSM) paradigm. Building on our preliminary work in this field, in this study, we provide a software-defined networking (SDN)-based framework that automates the detection and mitigation of slow-rate DDoS attacks. The framework uses deep learning (DL) to detect attacks and reinforcement learning (RL) to mitigate them. Furthermore, a network function virtualization (NFV)-assisted moving target defense (MTD) mechanism is included to amplify the effectiveness and flexibility of the solution. The framework is tested on a simulated network using open-source tools, namely Open Network Operating System (ONOS), Containernet, Apache Web Server, and Docker. The source code of a prototype of the framework is shared, which can be used and improved by interested researchers. Finally, the experimental results demonstrate that RL agents learn optimal DDoS mitigation policies in different scenarios and that they quickly adapt to new conditions that vary in short periods of time. & COPY; 2023 Elsevier B.V. All rights reserved.
引用
收藏
页码:637 / 649
页数:13
相关论文
共 50 条
  • [1] SDNShield: NFV-Based Defense Framework Against DDoS Attacks on SDN Control Plane
    Chen, Kuan-Yin
    Liu, Sen
    Xu, Yang
    Siddhrau, Ishant Kumar
    Zhou, Siyu
    Guo, Zehua
    Chao, H. Jonathan
    IEEE-ACM TRANSACTIONS ON NETWORKING, 2022, 30 (01) : 1 - 17
  • [2] A flexible SDN-based framework for slow-rate DDoS attack mitigation by reinforcement
    Yungaicela-Naula, Noe M.
    Vargas-Rosales, Cesar
    Perez-Diaz, Jesus Arturo
    Carrera, Diego Fernando
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2022, 205
  • [3] SDN/NFV-Based Moving Target DDoS Defense Mechanism
    Liu, Chien-Chang
    Huang, Bo-Sheng
    Tseng, Chia-Wei
    Yang, Yao-Tsung
    Chou, Li-Der
    RECENT TRENDS IN DATA SCIENCE AND SOFT COMPUTING, IRICT 2018, 2019, 843 : 548 - 556
  • [4] UDM: NFV-based prevention mechanism against DDoS attack on SDN controller
    Qian H.
    Xue H.
    Chen M.
    Tongxin Xuebao/Journal on Communications, 2019, 40 (03): : 116 - 124
  • [5] An NFV-Based Framework for Autonomous Deployment of New Protocols in SDN Networks
    Khater, Abbas
    Amirmasoud Noohi, Seyed
    Reza Hashemi, Massoud
    Zali, Zeinab
    IEEE ACCESS, 2024, 12 : 148727 - 148740
  • [6] A Cost-Effective Shuffling-Based Defense against HTTP DDoS Attacks with SDN/NFV
    Lin, Yi-Hui
    Kuo, Jian-Jhih
    Yang, De-Nian
    Chen, Wen-Tsuen
    2017 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2017,
  • [7] On an Integrated Security Framework for Defense Against Various DDoS Attacks in SDN
    Wu, Hao
    Hou, Aiqin
    Nie, Weike
    Wu, Chase
    2023 INTERNATIONAL CONFERENCE ON COMPUTING, NETWORKING AND COMMUNICATIONS, ICNC, 2023, : 311 - 317
  • [8] A Multi-Layered Defence Strategy against DDoS Attacks in SDN/NFV-Based 5G Mobile Networks
    Sheibani, Morteza
    Konur, Savas
    Awan, Irfan
    Qureshi, Amna
    ELECTRONICS, 2024, 13 (08)
  • [9] Implementation of an SDN-based Security Defense Mechanism Against DDoS Attacks
    Lin, Hsiao-Chung
    Wang, Ping
    JOINT 2016 INTERNATIONAL CONFERENCE ON ECONOMICS AND MANAGEMENT ENGINEERING (ICEME 2016) AND INTERNATIONAL CONFERENCE ON ECONOMICS AND BUSINESS MANAGEMENT (EBM 2016), 2016, : 377 - 383
  • [10] Risk-Aware SDN Defense Framework Against Anti-Honeypot Attacks Using Safe Reinforcement Learning
    Gao, Dongying
    Guo, Caiwei
    Zhang, Yi
    Ji, Wen
    Lv, Zhilei
    Li, Zheng
    Zhang, Kunsan
    Lin, Ruibin
    INTERNATIONAL JOURNAL OF NETWORK MANAGEMENT, 2024, 34 (06)