SDNScore: A Statistical Defense Mechanism Against DDoS Attacks in SDN Environment

被引:0
|
作者
Kalkan, Kubra [1 ,2 ]
Gur, Gurkan [2 ,3 ]
Alagoz, Fatih [2 ]
机构
[1] Istanbul Medeniyet Univ, Dept Comp Engn, Istanbul, Turkey
[2] Bogazici Univ, Dept Comp Engn, SATLAB, Istanbul, Turkey
[3] Bogazici Univ, TETAM, Istanbul, Turkey
关键词
SDN; network security; DDoS; filtering; defense mechanism;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Software Defined Networking (SDN) is a promising solution for addressing challenges of future networks. Despite its advantages such as flexibility, simplification and low costs, it has several drawbacks that are largely induced by the centralized control paradigm. Security is one of the most significant challenges related to centralization. In that regard, Distributed Denial of Service (DDoS) attacks pose crucial security questions in software-defined networks. In SDN architecture, switches send all packets to the controller if they do not have any applicable rules in their flow tables. Basically, controller is the key place that can take initiative in decisions. However, this characteristic results in large communication overhead and delay until a DDoS attack is detected and an appropriate action is activated against attack packets. Therefore, in this work we propose a hybrid mechanism, namely SDNScore, where switches are not simply data forwarders. Instead, they can collect statistics and decide if DDoS attack is in action. Then they coordinate with the controller and act on attack packets in cooperation. SDNScore is a statistical and packet-based defense mechanism against DDoS attacks in SDN environment. Since it has a statistical scoring method, it can detect not only known but also unknown attacks entailing packets that are alike in terms of TCP and IP layer properties. In addition, it does not drop all packets in a flow which includes both attack and legal packets, but rather filters out attack packets using packet-based analysis.
引用
收藏
页码:669 / 675
页数:7
相关论文
共 50 条
  • [1] Defense Mechanisms Against DDoS Attacks in SDN Environment
    Kalkan, Kubra
    Gur, Gurkan
    Alagoz, Fatih
    IEEE COMMUNICATIONS MAGAZINE, 2017, 55 (09) : 175 - 179
  • [2] Implementation of an SDN-based Security Defense Mechanism Against DDoS Attacks
    Lin, Hsiao-Chung
    Wang, Ping
    JOINT 2016 INTERNATIONAL CONFERENCE ON ECONOMICS AND MANAGEMENT ENGINEERING (ICEME 2016) AND INTERNATIONAL CONFERENCE ON ECONOMICS AND BUSINESS MANAGEMENT (EBM 2016), 2016, : 377 - 383
  • [3] A Responsive Defense Mechanism Against DDoS Attacks
    Mosharraf, Negar
    Jayasumana, Anura P.
    Ray, Indrakshi
    FOUNDATIONS AND PRACTICE OF SECURITY (FPS 2014), 2015, 8930 : 347 - 355
  • [4] Collaborative defense mechanism using statistical detection method against DDoS attacks
    Song, ByungHak
    Heo, Joon
    Hong, Choong Seon
    IEICE TRANSACTIONS ON COMMUNICATIONS, 2007, E90B (10) : 2655 - 2664
  • [5] On an Integrated Security Framework for Defense Against Various DDoS Attacks in SDN
    Wu, Hao
    Hou, Aiqin
    Nie, Weike
    Wu, Chase
    2023 INTERNATIONAL CONFERENCE ON COMPUTING, NETWORKING AND COMMUNICATIONS, ICNC, 2023, : 311 - 317
  • [6] Trilateral Trust Based Defense Mechanism against DDoS Attacks in Cloud Computing Environment
    Iyengar, N. Ch. S. N.
    Ganapathy, Gopinath
    CYBERNETICS AND INFORMATION TECHNOLOGIES, 2015, 15 (02) : 119 - 140
  • [7] MSOM: Efficient Mechanism for Defense against DDoS Attacks in VANET
    Al-Mehdhara, Mohammed
    Ruan, Na
    WIRELESS COMMUNICATIONS & MOBILE COMPUTING, 2021, 2021
  • [8] Multi-Defense Mechanism against DDoS in SDN based CDNi
    Nishat-I-Mowla
    Doh, Inshil
    Chae, Kijoon
    2014 Eighth International Conference on Innovative Mobile and Internet Services in Ubiquitous Computing (IMIS), 2014, : 447 - 451
  • [9] Collaborative Defense Method Against DDoS Attacks on SDN-Architected Cloud Servers
    Zhang, Yiying
    Xu, Yao
    Han, Longzhe
    Liang, Kun
    Li, Wenjing
    ADVANCED INTELLIGENT COMPUTING TECHNOLOGY AND APPLICATIONS, PT IV, ICIC 2024, 2024, 14865 : 362 - 370
  • [10] Source-Based Defense Against DDoS Attacks in SDN Based on sFlow and SOM
    Wang, Meng
    Lu, Yiqin
    Qin, Jiancheng
    IEEE ACCESS, 2022, 10 : 2097 - 2116