A traffic anomaly detection scheme for non-directional denial of service attacks in software-defined optical network

被引:1
|
作者
Liu, Tao [1 ,2 ]
Wang, He [1 ]
Zhang, Yuqing [1 ,2 ]
机构
[1] Xidian Univ, Sch Cyber Engn, Xian 710126, Peoples R China
[2] Univ Chinese Acad Sci, Natl Comp Network Intrus Protect Ctr, Beijing 100048, Peoples R China
基金
中国国家自然科学基金;
关键词
Software defined network; OpenFlow protocol; Security threat; Traffic anomaly detection; Denial of service attack; Controller; DDOS ATTACKS; TAXONOMY;
D O I
10.1016/j.cose.2021.102467
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
As a promising centralized control architecture, software-defined network (SDN) has been widely used and developed in the field of optical access network. Though, its centralized control architecture has many advantages, it is also hindered by various security threats. Among all the threats, the attack, Denial-of-Service (DoS) is the most severe attack into the software defined optical network (SDON). In spite of, so many developments in tools and technology, there are few effective schemes to detect denial of service attacks in SDON. In our research work, we proposed a traffic anomaly detection scheme by analyzing and defining the specific security threat non-directional denial of service attack (ND-DoS) faced by the SDON. In this scheme, we first designed the function construction of the controller and the extension of the OpenFlow protocol, and then used the adaptive threshold detection algorithm based on time sliding window (TSW-ATD) and the repeated flow detection algorithm (RFD) to complete the first detection and re-detection detection of abnormal traffic, and finally designed a general formulaic measurement method. The proposed scheme is verified by simulation experiments. The experimental results show that compared with the existing related solutions, the forwarding success rate of this scheme is increased by about 29.4%, the data processing rate in the unit window is increased by about 39.3%, and the CPU occupancy rate is reduced by about 17.5%. Therefore, this scheme can effectively deal with DoS attacks in SDON with a higher detection rate and lower resource overhead. (c) 2021 Published Elsevier Ltd.
引用
收藏
页数:13
相关论文
共 50 条
  • [41] Security in Software-Defined Networks Against Denial-of-Service Attacks Based on Increased Load Balancing Efficiency
    Zhang, Ying
    Ding, Hongwei
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2023, 14 (11) : 75 - 89
  • [42] Detection of Distributed Denial of Service Attacks using Machine Learning Algorithms in Software Defined Networks
    Meti, Nisharani
    Narayan, D. G.
    Baligar, V. P.
    2017 INTERNATIONAL CONFERENCE ON ADVANCES IN COMPUTING, COMMUNICATIONS AND INFORMATICS (ICACCI), 2017, : 1366 - 1371
  • [43] Federated Learning Based DDoS Attacks Detection in Large Scale Software-Defined Network
    Fotse, Yannis Steve Nsuloun
    Tchendji, Vianney Kengne
    Velempini, Mthulisi
    IEEE TRANSACTIONS ON COMPUTERS, 2025, 74 (01) : 101 - 115
  • [44] Implementing an intrusion detection and prevention system using software-defined networking: Defending against port-scanning and denial-of-service attacks
    Birkinshaw, Celyn
    Rouka, Elpida
    Vassilakis, Vassilios G.
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2019, 136 : 71 - 85
  • [45] A Probabilistic Data Structures-Based Anomaly Detection Scheme for Software-Defined Internet of Vehicles
    Garg, Sahil
    Singh, Amritpal
    Aujla, Gagangeet Singh
    Kaur, Sukhdeep
    Batra, Shalini
    Kumar, Neeraj
    IEEE TRANSACTIONS ON INTELLIGENT TRANSPORTATION SYSTEMS, 2021, 22 (06) : 3557 - 3566
  • [46] Statistical Approach Based Detection of Distributed Denial of Service Attack in a Software Defined Network
    Bavani, K.
    Ramkumar, M. P.
    Selvan, Emil G. S. R.
    2020 6TH INTERNATIONAL CONFERENCE ON ADVANCED COMPUTING AND COMMUNICATION SYSTEMS (ICACCS), 2020, : 380 - 385
  • [47] Distributed Denial of Service Attack Detection Based on Object Character in Software Defined Network
    Yao Linyuan
    Dong Ping
    Zhang Hongke
    JOURNAL OF ELECTRONICS & INFORMATION TECHNOLOGY, 2017, 39 (02) : 381 - 388
  • [48] A Framework for Distributed Denial of Service Attack Detection and Reactive Countermeasure in Software Defined Network
    Sangodoyin, Abimbola
    Mohammed, Bashir
    Moyo, Sibusiso
    Awan, Irfan
    Disso, Jules Pagna
    2019 7TH INTERNATIONAL CONFERENCE ON FUTURE INTERNET OF THINGS AND CLOUD (FICLOUD 2019), 2019, : 80 - 87
  • [49] SOFTWARE-DEFINED OPTICAL LOCAL AREA NETWORK ARCHITECTURE AND PRIORITY TRAFFIC PERFORMANCE ANALYSIS
    Baziana, Peristera A.
    PROCEEDINGS OF THE 2022 ANNUAL MODELING AND SIMULATION CONFERENCE (ANNSIM'22), 2022, : 767 - 777
  • [50] Residual based temporal attention convolutional neural network for detection of distributed denial of service attacks in software defined network integrated vehicular adhoc network
    Karthik, V.
    Lakshmi, R.
    Abraham, Salini
    Ramkumar, M.
    INTERNATIONAL JOURNAL OF NETWORK MANAGEMENT, 2024, 34 (03)