A traffic anomaly detection scheme for non-directional denial of service attacks in software-defined optical network

被引:1
|
作者
Liu, Tao [1 ,2 ]
Wang, He [1 ]
Zhang, Yuqing [1 ,2 ]
机构
[1] Xidian Univ, Sch Cyber Engn, Xian 710126, Peoples R China
[2] Univ Chinese Acad Sci, Natl Comp Network Intrus Protect Ctr, Beijing 100048, Peoples R China
基金
中国国家自然科学基金;
关键词
Software defined network; OpenFlow protocol; Security threat; Traffic anomaly detection; Denial of service attack; Controller; DDOS ATTACKS; TAXONOMY;
D O I
10.1016/j.cose.2021.102467
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
As a promising centralized control architecture, software-defined network (SDN) has been widely used and developed in the field of optical access network. Though, its centralized control architecture has many advantages, it is also hindered by various security threats. Among all the threats, the attack, Denial-of-Service (DoS) is the most severe attack into the software defined optical network (SDON). In spite of, so many developments in tools and technology, there are few effective schemes to detect denial of service attacks in SDON. In our research work, we proposed a traffic anomaly detection scheme by analyzing and defining the specific security threat non-directional denial of service attack (ND-DoS) faced by the SDON. In this scheme, we first designed the function construction of the controller and the extension of the OpenFlow protocol, and then used the adaptive threshold detection algorithm based on time sliding window (TSW-ATD) and the repeated flow detection algorithm (RFD) to complete the first detection and re-detection detection of abnormal traffic, and finally designed a general formulaic measurement method. The proposed scheme is verified by simulation experiments. The experimental results show that compared with the existing related solutions, the forwarding success rate of this scheme is increased by about 29.4%, the data processing rate in the unit window is increased by about 39.3%, and the CPU occupancy rate is reduced by about 17.5%. Therefore, this scheme can effectively deal with DoS attacks in SDON with a higher detection rate and lower resource overhead. (c) 2021 Published Elsevier Ltd.
引用
收藏
页数:13
相关论文
共 50 条
  • [1] Collaborative Detection and Mitigation of Distributed Denial-of-Service Attacks on Software-Defined Network
    Omer Elsier Tayfour
    Muhammad Nadzir Marsono
    Mobile Networks and Applications, 2020, 25 : 1338 - 1347
  • [2] Collaborative Detection and Mitigation of Distributed Denial-of-Service Attacks on Software-Defined Network
    Tayfour, Omer Elsier
    Marsono, Muhammad Nadzir
    MOBILE NETWORKS & APPLICATIONS, 2020, 25 (04): : 1338 - 1347
  • [3] Denial of Service Attacks Detection in Software-Defined Wireless Sensor Networks
    Nunez Segura, Gustavo A.
    Skaperas, Sotiris
    Chorti, Arsenia
    Mamatas, Lefteris
    Margi, Cintia Borges
    2020 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS WORKSHOPS (ICC WORKSHOPS), 2020,
  • [4] Investigating high traffic rate distributed denial of service attacks detection mechanisms in Software-Defined Networks
    Sejaphala, Lanka Chris
    Velempini, Mthulisi
    2018 CONFERENCE ON INFORMATION COMMUNICATIONS TECHNOLOGY AND SOCIETY (ICTAS), 2018,
  • [5] A Testbed for the Evaluation of Denial of Service Attacks in Software-Defined Networks
    Wright, Andrea P.
    Ghani, Nasir
    2019 IEEE SOUTHEASTCON, 2019,
  • [6] Early Detection of Distributed Denial of Service Attack in Era of Software-Defined Network
    Joshi, Bineet Kumar
    Joshi, Nitin
    Joshi, Mahesh Chandra
    2018 ELEVENTH INTERNATIONAL CONFERENCE ON CONTEMPORARY COMPUTING (IC3), 2018, : 347 - 349
  • [7] DoSGuard: Mitigating Denial-of-Service Attacks in Software-Defined Networks
    Li, Jishuai
    Tu, Tengfei
    Li, Yongsheng
    Qin, Sujuan
    Shi, Yijie
    Wen, Qiaoyan
    SENSORS, 2022, 22 (03)
  • [8] Distributed Denial of Service Attacks in Software-Defined Networking with Cloud Computing
    Yan, Qiao
    Yu, F. Richard
    IEEE COMMUNICATIONS MAGAZINE, 2015, 53 (04) : 52 - 59
  • [9] Distributed Denial of Service (DDoS) Attacks in Software-defined Networks (SDN)
    Chahal, Jasmeen Kaur
    Kaur, Puninder
    Sharma, Avinash
    2021 5TH INTERNATIONAL CONFERENCE ON ELECTRICAL, ELECTRONICS, COMMUNICATION, COMPUTER TECHNOLOGIES AND OPTIMIZATION TECHNIQUES (ICEECCOT), 2021, : 291 - 295
  • [10] A robust tuned classifier-based distributed denial of service attacks detection for quality of service enhancement in software-defined network
    Kaur, Gaganjot
    Gupta, Prinima
    JOURNAL OF INTELLIGENT & FUZZY SYSTEMS, 2022, 43 (03) : 2693 - 2710