Traffic Monitoring and DDoS Detection using Stateful SDN

被引:0
|
作者
Rebecchi, Filippo [1 ]
Boite, Julien [1 ]
Nardin, Pierre-Alexis [1 ]
Bouet, Mathieu [1 ]
Conan, Vania [1 ]
机构
[1] Thales Commun & Secur, Gennevilliers, France
关键词
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
We propose to showcase the benefits of stateful SDN in the context of DDoS detection and mitigation. By delegating some local tasks to the switch rather than relying always on the controller, it is possible to monitor data-plane traffic efficiently and to detect malicious network behaviours with high accuracy. Stateful SDN concepts are employed both to improve reactivity and to offload the controller and the control channel by delegating local treatments down to the switches. The demo illustrates how to protect end-hosts from Distributed Denial of Service (DDoS) attacks. Our approach, named StateSec, is built on advanced in-switch processing capabilities to detect and mitigate threats swiftly. StateSec relies on a detection loop to: 1) match and count a configurable set of traffic features (e.g., IP source and destination, port source and destination) without resorting to the controller; 2) use an entropy-based detection algorithm with such monitored features, 3) detect several threats such as (D) DoS and port scans with high accuracy, and 4) take countermeasures by installing OpenFlow rules at the switch.
引用
收藏
页数:2
相关论文
共 50 条
  • [31] DDoS Attack Detection under SDN Context
    Xu, Yang
    Liu, Yong
    IEEE INFOCOM 2016 - THE 35TH ANNUAL IEEE INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATIONS, 2016,
  • [32] Analyzing behavior of DDoS attacks to identify DDoS detection features in SDN
    Dayal, Neelam
    Srivastava, Shashank
    2017 9TH INTERNATIONAL CONFERENCE ON COMMUNICATION SYSTEMS AND NETWORKS (COMSNETS), 2017, : 274 - 281
  • [33] SOFTmon - Traffic Monitoring for SDN
    Hartung, Marc
    Koerner, Marc
    14TH INTERNATIONAL CONFERENCE ON MOBILE SYSTEMS AND PERVASIVE COMPUTING (MOBISPC 2017) / 12TH INTERNATIONAL CONFERENCE ON FUTURE NETWORKS AND COMMUNICATIONS (FNC 2017) / AFFILIATED WORKSHOPS, 2017, 110 : 516 - 523
  • [34] Review of Research on DDoS Attack Detection in SDN
    Zheng, Chengwei
    Wang, Haifeng
    Liu, Rui
    Computer Engineering and Applications, 2024, 60 (24) : 79 - 96
  • [35] An Efficient DDoS Detection with Bloom Filter in SDN
    Xiao, Peng
    Li, Zhiyang
    Qi, Heng
    Qu, Wenyu
    Yu, Haisheng
    2016 IEEE TRUSTCOM/BIGDATASE/ISPA, 2016, : 1 - 6
  • [36] A Comprehensive and Effective Mechanism for DDoS Detection in SDN
    Conti, Mauro
    Gangwal, Ankit
    Gaur, Manoj Singh
    2017 IEEE 13TH INTERNATIONAL CONFERENCE ON WIRELESS AND MOBILE COMPUTING, NETWORKING AND COMMUNICATIONS (WIMOB), 2017, : 684 - 691
  • [37] The Current Trends of DDoS Detection in SDN Environment
    Kareem, Mohammed Ibrahim
    Jasim, Mandi Nsaif
    PROCEEDING OF 2021 2ND INFORMATION TECHNOLOGY TO ENHANCE E-LEARNING AND OTHER APPLICATION (IT-ELA 2021), 2021, : 29 - 34
  • [38] DDoS Defense using MTD and SDN
    Steinberger, Jessica
    Kuhnert, Benjamin
    Dietz, Christian
    Ball, Lisa
    Sperotto, Anna
    Baier, Harald
    Pras, Aiko
    Dreo, Gabi
    NOMS 2018 - 2018 IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM, 2018,
  • [39] A DDoS protection method based on traffic scheduling and scrubbing in SDN
    Yu, Yiwei
    Cheng, Guang
    Chen, Zihan
    Ding, Haoxuan
    2021 17TH INTERNATIONAL CONFERENCE ON MOBILITY, SENSING AND NETWORKING (MSN 2021), 2021, : 758 - 765
  • [40] Fast failure detection and recovery in SDN with stateful data plane
    Cascone, Carmelo
    Sanvito, Davide
    Pollini, Luca
    Capone, Antonio
    Sanso, Brunilde
    INTERNATIONAL JOURNAL OF NETWORK MANAGEMENT, 2017, 27 (02)