K-DDoS-SDN: A distributed DDoS attacks detection approach for protecting SDN environment

被引:3
|
作者
Kaur, Amandeep [1 ]
Krishna, C. Rama [1 ]
Patil, Nilesh Vishwasrao [2 ]
机构
[1] Natl Inst Tech Teachers Training & Res, Dept Comp Sci & Engn, Chandigarh, India
[2] Govt Polytech, Dept Comp Engn, Aurangabad, Maharashtra, India
来源
关键词
apache kafka streams; distributed detection approach; DDoS attacks; network security; software-defined networking; DEFENSE-MECHANISMS;
D O I
10.1002/cpe.7912
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Software-defined networking (SDN) is an advanced networking paradigm that decouples forwarding control logic from the data plane. Therefore, it provides a loosely-coupled architecture between the control and data plane. This separation provides flexibility in the SDN environment for addressing any transformations. Further, it delivers a centralized way of managing networks due to control logic embedded in the SDN controller. However, this advanced networking paradigm has been facing several security issues, such as topology spoofing, exhausting bandwidth, flow table updating, and distributed denial of service (DDoS) attacks. A DDoS attack is one of the most powerful menaces to the SDN environment. Further, the central data controller of SDN becomes the primary target of DDoS attacks. In this article, we propose a Kafka-based distributed DDoS attacks detection approach for protecting the SDN environment named K-DDoS-SDN. The K-DDoS-SDN consists of two modules: (i) Network traffic classification (NTClassification) module and (ii) Network traffic storage (NTStorage) module. The NTClassification module is the detection approach designed using scalable H2O ML techniques in a distributed manner and deployed an efficient model on the two-nodes Kafka Streams cluster to classify incoming network traces in real-time. The NTStorage module collects raw packets, network flows, and 21 essential attributes and then systematically stores them in the HDFS to re-train existing models. The proposed K-DDoS-SDN designed and evaluated using the recent and publically available CICDDoS2019 dataset. The average classification accuracy of the proposed distributed K-DDoS-SDN for classifying network traces into legitimate and one of the most popular attacks, such as DDoS_UDP is 99.22%. Further, the outcomes demonstrate that proposed distributed K-DDoS-SDN classifies traffic traces into five categories with at least 81% classification accuracy.
引用
收藏
页数:19
相关论文
共 50 条
  • [41] IQR-based approach for DDoS detection and mitigation in SDN
    Swami, Rochak
    Dave, Mayank
    Ranga, Virender
    DEFENCE TECHNOLOGY, 2023, 25 : 76 - 87
  • [42] Detection and Mitigation of DoS and DDoS Attacks in IoT-Based Stateful SDN: An Experimental Approach
    Galeano-Brajones, Jesus
    Carmona-Murillo, Javier
    Valenzuela-Valdes, Juan F.
    Luna-Valero, Francisco
    SENSORS, 2020, 20 (03)
  • [43] Improved K-means-based solution for detecting DDoS attacks in SDN
    Qian, Haizhong
    Cai, Lili
    PHYSICAL COMMUNICATION, 2024, 64
  • [44] The Design of SDN based Detection for Distributed Denial of Service (DDoS) attack
    Oo, Myo Myint
    Kamolphiwong, Sinchai
    Kamolphiwong, Thossaporn
    2017 21ST INTERNATIONAL COMPUTER SCIENCE AND ENGINEERING CONFERENCE (ICSEC 2017), 2017, : 258 - 263
  • [45] DDoS Attack Detection under SDN Context
    Xu, Yang
    Liu, Yong
    IEEE INFOCOM 2016 - THE 35TH ANNUAL IEEE INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATIONS, 2016,
  • [46] Review of Research on DDoS Attack Detection in SDN
    Zheng, Chengwei
    Wang, Haifeng
    Liu, Rui
    Computer Engineering and Applications, 2024, 60 (24) : 79 - 96
  • [47] An Efficient DDoS Detection with Bloom Filter in SDN
    Xiao, Peng
    Li, Zhiyang
    Qi, Heng
    Qu, Wenyu
    Yu, Haisheng
    2016 IEEE TRUSTCOM/BIGDATASE/ISPA, 2016, : 1 - 6
  • [48] Detection and mitigation of DDoS attacks based on multi-dimensional characteristics in SDN
    Wang, Kun
    Fu, Yu
    Duan, Xueyuan
    Liu, Taotao
    SCIENTIFIC REPORTS, 2024, 14 (01):
  • [49] A Comprehensive and Effective Mechanism for DDoS Detection in SDN
    Conti, Mauro
    Gangwal, Ankit
    Gaur, Manoj Singh
    2017 IEEE 13TH INTERNATIONAL CONFERENCE ON WIRELESS AND MOBILE COMPUTING, NETWORKING AND COMMUNICATIONS (WIMOB), 2017, : 684 - 691
  • [50] CTMBIDS: convolutional Tsetlin machine-based intrusion detection system for DDoS attacks in an SDN environment
    Rasoul Jafari Gohari
    Laya Aliahmadipour
    Marjan Kuchaki Rafsanjani
    Neural Computing and Applications, 2025, 37 (9) : 6795 - 6818