A Flexible SDN-Based Architecture for Identifying and Mitigating Low-Rate DDoS Attacks Using Machine Learning

被引:125
|
作者
Arturo Perez-Diaz, Jesus [1 ]
Amezcua Valdovinos, Ismael [2 ]
Choo, Kim-Kwang Raymond [3 ,4 ]
Zhu, Dakai [4 ]
机构
[1] Tecnol Monterrey, Escuela Ingn & Ciencias, Monterrey 64849, Mexico
[2] Univ Colima, Fac Telemat, Colima 28040, Mexico
[3] Univ Texas San Antonio, Dept Informat Syst & Cyber Secur, San Antonio, TX 78249 USA
[4] Univ Texas San Antonio, Dept Comp Sci, San Antonio, TX 78249 USA
来源
IEEE ACCESS | 2020年 / 8卷 / 08期
关键词
Computer crime; Computer architecture; Machine learning; Vegetation; Support vector machines; Control systems; IP networks; DDoS attack mitigation; low-rate DDoS (LR-DDoS) attacks; machine learning; software-defined network (SDN); INTRUSION DETECTION; SERVICE ATTACKS; SYSTEM;
D O I
10.1109/ACCESS.2020.3019330
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
While there have been extensive studies of denial of service (DoS) attacks and DDoS attack mitigation, such attacks remain challenging to mitigate. For example, Low-Rate DDoS (LR-DDoS) attacks are known to be difficult to detect, particularly in a software-defined network (SDN). Hence, in this paper we present a flexible modular architecture that allows the identification and mitigation of LR-DDoS attacks in SDN settings. Specifically, we train the intrusion detection system (IDS) in our architecture using six machine learning (ML) models (i.e., J48, Random Tree, REP Tree, Random Forest, Multi-Layer Perceptron (MLP), and Support Vector Machines (SVM)) and evaluate their performance using the Canadian Institute of Cybersecurity (CIC) DoS dataset. The findings from the evaluation demonstrate that our approach achieves a detection rate of 95%, despite the difficulty in detecting LR-DoS attacks. We also remark that in our deployment, we use the open network operating system (ONOS) controller running on Mininet virtual machine in order for our simulated environment to be as close to real-world production networks as possible. In our testing topology, the intrusion prevention detection system mitigates all attacks previously detected by the IDS system. This demonstrates the utility of our architecture in identifying and mitigating LR-DDoS attacks.
引用
收藏
页码:155859 / 155872
页数:14
相关论文
共 50 条
  • [21] Detecting DDoS Attacks in SDN using a Hybrid Method with Entropy and Machine Learning
    Santos-Neto, Marcos J.
    Bordim, Jacir L.
    Alchieri, Eduardo A. P.
    Ishikawa, Edison
    Dourado, Leonardo S.
    2022 TENTH INTERNATIONAL SYMPOSIUM ON COMPUTING AND NETWORKING WORKSHOPS, CANDARW, 2022, : 248 - 254
  • [22] Defending SDN-based IoT Networks Against DDoS Attacks Using Markov Decision Process
    Zheng, Jianjun
    Namin, Akbar Siami
    2018 IEEE INTERNATIONAL CONFERENCE ON BIG DATA (BIG DATA), 2018, : 4589 - 4592
  • [23] DDoS Detection and Analysis in SDN-based Environment Using Support Vector Machine Classifier
    Kokila, R. T.
    Selvi, S. Thamarai
    Govindarajan, Kannan
    2014 SIXTH INTERNATIONAL CONFERENCE ON ADVANCED COMPUTING, 2014, : 205 - 210
  • [24] Detection of Low-Rate Cloud DDoS Attacks in Frequency Domain Using Fast Hartley Transform
    Neha Agrawal
    Shashikala Tapaswi
    Wireless Personal Communications, 2020, 112 : 1735 - 1762
  • [25] Detection of Low-Rate Cloud DDoS Attacks in Frequency Domain Using Fast Hartley Transform
    Agrawal, Neha
    Tapaswi, Shashikala
    WIRELESS PERSONAL COMMUNICATIONS, 2020, 112 (03) : 1735 - 1762
  • [26] Low-rate DDoS attacks detection method using data compression and behavior divergence measurement
    Liu, Xinqian
    Ren, Jiadong
    He, Haitao
    Wang, Qian
    Song, Chen
    COMPUTERS & SECURITY, 2021, 100
  • [27] Low-Rate DDoS Attack Detection Based on Factorization Machine in Software Defined Network
    Wu Zhijun
    Xu Qing
    Wang Jingjie
    Yue Meng
    Liu Liang
    IEEE ACCESS, 2020, 8 : 17404 - 17418
  • [28] SDN-based In-Band DDoS Detection Using Ensemble Learning Algorithm on IoT Edge
    Zang, Mingyuan
    Zaballa, Eder Ollora
    Dittmann, Lars
    25TH CONFERENCE ON INNOVATION IN CLOUDS, INTERNET AND NETWORKS (ICIN 2022), 2022, : 111 - 115
  • [29] Low-Rate DoS Attack Detection Using PSD based Entropy and Machine Learning
    Zhang, Naiji
    Jaafar, Fehmi
    Malik, Yasir
    2019 6TH IEEE INTERNATIONAL CONFERENCE ON CYBER SECURITY AND CLOUD COMPUTING (IEEE CSCLOUD 2019) / 2019 5TH IEEE INTERNATIONAL CONFERENCE ON EDGE COMPUTING AND SCALABLE CLOUD (IEEE EDGECOM 2019), 2019, : 59 - 62
  • [30] DDoS Attack Identification and Defense using SDN based on Machine Learning Method
    Yang Lingfeng
    Zhao Hui
    2018 15TH INTERNATIONAL SYMPOSIUM ON PERVASIVE SYSTEMS, ALGORITHMS AND NETWORKS (I-SPAN 2018), 2018, : 166 - 170