Traffic Monitoring and DDoS Detection using Stateful SDN

被引:0
|
作者
Rebecchi, Filippo [1 ]
Boite, Julien [1 ]
Nardin, Pierre-Alexis [1 ]
Bouet, Mathieu [1 ]
Conan, Vania [1 ]
机构
[1] Thales Commun & Secur, Gennevilliers, France
关键词
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
We propose to showcase the benefits of stateful SDN in the context of DDoS detection and mitigation. By delegating some local tasks to the switch rather than relying always on the controller, it is possible to monitor data-plane traffic efficiently and to detect malicious network behaviours with high accuracy. Stateful SDN concepts are employed both to improve reactivity and to offload the controller and the control channel by delegating local treatments down to the switches. The demo illustrates how to protect end-hosts from Distributed Denial of Service (DDoS) attacks. Our approach, named StateSec, is built on advanced in-switch processing capabilities to detect and mitigate threats swiftly. StateSec relies on a detection loop to: 1) match and count a configurable set of traffic features (e.g., IP source and destination, port source and destination) without resorting to the controller; 2) use an entropy-based detection algorithm with such monitored features, 3) detect several threats such as (D) DoS and port scans with high accuracy, and 4) take countermeasures by installing OpenFlow rules at the switch.
引用
收藏
页数:2
相关论文
共 50 条
  • [41] Enhanced DDoS Detection using Hybrid Genetic Algorithm and Decision Tree for SDN
    Preamthaisong, Parinya
    Auyporntrakool, Anucha
    Aimtongkham, Phet
    Sriwuttisap, Titaya
    So-In, Chakchai
    2019 16TH INTERNATIONAL JOINT CONFERENCE ON COMPUTER SCIENCE AND SOFTWARE ENGINEERING (JCSSE 2019), 2019, : 152 - 157
  • [42] DDoS attack detection and mitigation using deep neural network in SDN environment
    Hnamte, Vanlalruata
    Najar, Ashfaq Ahmad
    Hong, Nhung-Nguyen
    Hussain, Jamal
    Sugali, Manohar Naik
    COMPUTERS & SECURITY, 2024, 138
  • [43] Detection of DDoS attacks in SDN-based VANET using optimized TabNet
    Setitra, Mohamed Ali
    Fan, Mingyu
    COMPUTER STANDARDS & INTERFACES, 2024, 90
  • [44] IoT-Based DDoS Attack Detection and Mitigation Using the Edge of SDN
    Yang, Yinqi
    Wang, Jian
    Zhai, Baoqin
    Liu, Jiqiang
    CYBERSPACE SAFETY AND SECURITY, PT II, 2019, 11983 : 3 - 17
  • [45] A lightweight DDoS detection scheme under SDN context
    Jia, Kun
    Liu, Chaoge
    Liu, Qixu
    Wang, Junnan
    Liu, Jiazhi
    Liu, Feng
    CYBERSECURITY, 2022, 5 (01)
  • [46] A Collaborative Intrusion Detection System against DDoS for SDN
    Chen, Xiaofan
    Yu, Shunzheng
    IEICE TRANSACTIONS ON INFORMATION AND SYSTEMS, 2016, E99D (09) : 2395 - 2399
  • [47] Early detection of DDoS based on φ-entropy in SDN networks
    Li, Runyu
    Wu, Bin
    PROCEEDINGS OF 2020 IEEE 4TH INFORMATION TECHNOLOGY, NETWORKING, ELECTRONIC AND AUTOMATION CONTROL CONFERENCE (ITNEC 2020), 2020, : 731 - 735
  • [48] An Improved Method of DDoS Attack Detection for Controller of SDN
    Sun, Wenwen
    Li, Yi
    Guan, Shaopeng
    2019 IEEE 2ND INTERNATIONAL CONFERENCE ON COMPUTER AND COMMUNICATION ENGINEERING TECHNOLOGY (CCET), 2019, : 249 - 253
  • [49] Early Detection of DDoS Attacks against SDN Controllers
    Mousavi, Seyed Mohammad
    St-Hilaire, Marc
    2015 INTERNATIONAL CONFERENCE ON COMPUTING, NETWORKING AND COMMUNICATIONS (ICNC), 2015, : 77 - 81
  • [50] A Detection Method for DDoS Attack against SDN Controller
    Meng, Linhai
    Guo, Xiao
    PROCEEDINGS OF THE 4TH ANNUAL INTERNATIONAL CONFERENCE ON MATERIAL ENGINEERING AND APPLICATION (ICMEA 2017), 2017, 146 : 292 - 296