K-DDoS-SDN: A distributed DDoS attacks detection approach for protecting SDN environment

被引:3
|
作者
Kaur, Amandeep [1 ]
Krishna, C. Rama [1 ]
Patil, Nilesh Vishwasrao [2 ]
机构
[1] Natl Inst Tech Teachers Training & Res, Dept Comp Sci & Engn, Chandigarh, India
[2] Govt Polytech, Dept Comp Engn, Aurangabad, Maharashtra, India
来源
关键词
apache kafka streams; distributed detection approach; DDoS attacks; network security; software-defined networking; DEFENSE-MECHANISMS;
D O I
10.1002/cpe.7912
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Software-defined networking (SDN) is an advanced networking paradigm that decouples forwarding control logic from the data plane. Therefore, it provides a loosely-coupled architecture between the control and data plane. This separation provides flexibility in the SDN environment for addressing any transformations. Further, it delivers a centralized way of managing networks due to control logic embedded in the SDN controller. However, this advanced networking paradigm has been facing several security issues, such as topology spoofing, exhausting bandwidth, flow table updating, and distributed denial of service (DDoS) attacks. A DDoS attack is one of the most powerful menaces to the SDN environment. Further, the central data controller of SDN becomes the primary target of DDoS attacks. In this article, we propose a Kafka-based distributed DDoS attacks detection approach for protecting the SDN environment named K-DDoS-SDN. The K-DDoS-SDN consists of two modules: (i) Network traffic classification (NTClassification) module and (ii) Network traffic storage (NTStorage) module. The NTClassification module is the detection approach designed using scalable H2O ML techniques in a distributed manner and deployed an efficient model on the two-nodes Kafka Streams cluster to classify incoming network traces in real-time. The NTStorage module collects raw packets, network flows, and 21 essential attributes and then systematically stores them in the HDFS to re-train existing models. The proposed K-DDoS-SDN designed and evaluated using the recent and publically available CICDDoS2019 dataset. The average classification accuracy of the proposed distributed K-DDoS-SDN for classifying network traces into legitimate and one of the most popular attacks, such as DDoS_UDP is 99.22%. Further, the outcomes demonstrate that proposed distributed K-DDoS-SDN classifies traffic traces into five categories with at least 81% classification accuracy.
引用
收藏
页数:19
相关论文
共 50 条
  • [1] Analyzing behavior of DDoS attacks to identify DDoS detection features in SDN
    Dayal, Neelam
    Srivastava, Shashank
    2017 9TH INTERNATIONAL CONFERENCE ON COMMUNICATION SYSTEMS AND NETWORKS (COMSNETS), 2017, : 274 - 281
  • [2] New distributed SDN framework for mitigating DDoS attacks
    Alshehhi A.
    Yeun C.Y.
    Damiani E.
    Transactions of the Korean Institute of Electrical Engineers, 2017, 66 (12): : 1913 - 1920
  • [3] Lightweight Algorithm for Protecting SDN controller against DDoS attacks
    Gkountis, Christos
    Taha, Miran
    Lloret, Jaime
    Kambourakis, Georgios
    2017 10TH IFIP WIRELESS AND MOBILE NETWORKING CONFERENCE (WMNC 2017), 2017,
  • [4] DNS Amplification Based DDoS Attacks in SDN Environment: Detection and Mitigation
    Gupta, Vishal
    Kochar, Amrit
    Saharan, Shail
    Kulshrestha, Rakhee
    2019 IEEE 4TH INTERNATIONAL CONFERENCE ON COMPUTER AND COMMUNICATION SYSTEMS (ICCCS 2019), 2019, : 473 - 478
  • [5] Defense Mechanisms Against DDoS Attacks in SDN Environment
    Kalkan, Kubra
    Gur, Gurkan
    Alagoz, Fatih
    IEEE COMMUNICATIONS MAGAZINE, 2017, 55 (09) : 175 - 179
  • [6] An Efficient IDS Framework for DDoS Attacks in SDN Environment
    Varghese, Josy Elsa
    Muniyal, Balachandra
    IEEE ACCESS, 2021, 9 : 69680 - 69699
  • [7] The Current Trends of DDoS Detection in SDN Environment
    Kareem, Mohammed Ibrahim
    Jasim, Mandi Nsaif
    PROCEEDING OF 2021 2ND INFORMATION TECHNOLOGY TO ENHANCE E-LEARNING AND OTHER APPLICATION (IT-ELA 2021), 2021, : 29 - 34
  • [8] Early Detection of DDoS Attacks against SDN Controllers
    Mousavi, Seyed Mohammad
    St-Hilaire, Marc
    2015 INTERNATIONAL CONFERENCE ON COMPUTING, NETWORKING AND COMMUNICATIONS (ICNC), 2015, : 77 - 81
  • [9] Prevention and Mitigation of DNS based DDoS attacks in SDN Environment
    Saharan, Shail
    Gupta, Vishal
    2019 11TH INTERNATIONAL CONFERENCE ON COMMUNICATION SYSTEMS & NETWORKS (COMSNETS), 2019, : 606 - 608
  • [10] Detection and mitigation of DDoS in SDN
    Pande, Bhavika
    Bhagat, Gargi
    Priya, Shanu
    Agrawal, Himanshu
    2018 ELEVENTH INTERNATIONAL CONFERENCE ON CONTEMPORARY COMPUTING (IC3), 2018, : 371 - 373