SDNScore: A Statistical Defense Mechanism Against DDoS Attacks in SDN Environment

被引:0
|
作者
Kalkan, Kubra [1 ,2 ]
Gur, Gurkan [2 ,3 ]
Alagoz, Fatih [2 ]
机构
[1] Istanbul Medeniyet Univ, Dept Comp Engn, Istanbul, Turkey
[2] Bogazici Univ, Dept Comp Engn, SATLAB, Istanbul, Turkey
[3] Bogazici Univ, TETAM, Istanbul, Turkey
关键词
SDN; network security; DDoS; filtering; defense mechanism;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Software Defined Networking (SDN) is a promising solution for addressing challenges of future networks. Despite its advantages such as flexibility, simplification and low costs, it has several drawbacks that are largely induced by the centralized control paradigm. Security is one of the most significant challenges related to centralization. In that regard, Distributed Denial of Service (DDoS) attacks pose crucial security questions in software-defined networks. In SDN architecture, switches send all packets to the controller if they do not have any applicable rules in their flow tables. Basically, controller is the key place that can take initiative in decisions. However, this characteristic results in large communication overhead and delay until a DDoS attack is detected and an appropriate action is activated against attack packets. Therefore, in this work we propose a hybrid mechanism, namely SDNScore, where switches are not simply data forwarders. Instead, they can collect statistics and decide if DDoS attack is in action. Then they coordinate with the controller and act on attack packets in cooperation. SDNScore is a statistical and packet-based defense mechanism against DDoS attacks in SDN environment. Since it has a statistical scoring method, it can detect not only known but also unknown attacks entailing packets that are alike in terms of TCP and IP layer properties. In addition, it does not drop all packets in a flow which includes both attack and legal packets, but rather filters out attack packets using packet-based analysis.
引用
收藏
页码:669 / 675
页数:7
相关论文
共 50 条
  • [41] Detection and Defense Mechanisms Against DDoS Attacks: A Review
    Pimpalkar, Archana S.
    Patil, A. R. Bhagat
    2015 INTERNATIONAL CONFERENCE ON INNOVATIONS IN INFORMATION, EMBEDDED AND COMMUNICATION SYSTEMS (ICIIECS), 2015,
  • [42] A Statistical Model for Early Detection of DDoS Attacks on Random Targets in SDN
    Reza Bakhtiari Shohani
    Seyedakbar Mostafavi
    Vesal Hakami
    Wireless Personal Communications, 2021, 120 : 379 - 400
  • [43] Efficient Joint Detection and Defense Mechanism for DDoS Attack in SDN
    Zeng R.-F.
    Gao Y.
    Wang X.-W.
    Zhang B.
    Dongbei Daxue Xuebao/Journal of Northeastern University, 2020, 41 (09): : 1217 - 1222
  • [44] SDN, A Research on SDN Assets and Tools to Defense DDoS Attack in Cloud Computing Environment
    Tamanna, Tasnim
    Fatema, Tasmiah
    Saha, Reepa
    2017 2ND IEEE INTERNATIONAL CONFERENCE ON WIRELESS COMMUNICATIONS, SIGNAL PROCESSING AND NETWORKING (WISPNET), 2017, : 1670 - 1674
  • [45] A new and comprehensive taxonomy of DDoS attacks and defense mechanism
    Asosheh, Abbass
    Ramezani, Naghmeh
    PROCEEDINGS OF THE 6TH WSEAS INTERNATIONAL CONFERENCE ON INFORMATION SECURITY AND PRIVACY (ISP '07): ADVANCED TOPICS IN INFORMATION SECURITY AND PRIVACY, 2007, : 178 - 183
  • [46] An efficient DDoS attack detection mechanism in SDN environment
    Hnamte V.
    Hussain J.
    International Journal of Information Technology, 2023, 15 (5) : 2623 - 2636
  • [47] DNS Amplification Based DDoS Attacks in SDN Environment: Detection and Mitigation
    Gupta, Vishal
    Kochar, Amrit
    Saharan, Shail
    Kulshrestha, Rakhee
    2019 IEEE 4TH INTERNATIONAL CONFERENCE ON COMPUTER AND COMMUNICATION SYSTEMS (ICCCS 2019), 2019, : 473 - 478
  • [48] A Distributed Mechanism to Protect Against DDoS Attacks
    Mosharraf, Negar
    Jayasumana, Anura P.
    Ray, Indrakshi
    DATA AND APPLICATIONS SECURITY AND PRIVACY XXXI, DBSEC 2017, 2017, 10359 : 529 - 540
  • [49] An SDN-based Approach For Defending Against Reflective DDoS Attacks
    Lukaseder, Thomas
    StOlzle, Kevin
    Kleber, Stephan
    Erb, Benjamin
    Kargl, Frank
    PROCEEDINGS OF THE 2018 IEEE 43RD CONFERENCE ON LOCAL COMPUTER NETWORKS (LCN), 2018, : 299 - 302
  • [50] Framework for statistical filtering against DDoS attacks in MANETs
    Tan, HX
    Seah, WKG
    ICESS 2005: SECOND INTERNATIONAL CONFERENCE ON EMBEDDED SOFTWARE AND SYSTEMS, 2005, : 456 - 463