A Novel Feature-Based DDoS Detection and Mitigation Scheme in SDN Controller Using Queueing Theory

被引:7
|
作者
Tahmasebi, Ava [1 ]
Salahi, Ahmad [2 ]
Pourmina, Mohammad Ali [1 ]
机构
[1] Islamic Azad Univ, Fac Mech Elect & Comp Engn, Sci & Res Branch, Tehran, Iran
[2] Iran Telecommun Res Ctr, Commun Technol Inst, Tehran, Iran
关键词
Software defined network (SDN); Feature extraction; Distributed denial of service (DDoS); Queueing theory; Controller utilization; ATTACK;
D O I
10.1007/s11277-020-07954-3
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
Software defined network (SDN) has attracted great interests as an emergent paradigm which aims to centralize the configuration of network devices by decoupling control layer and data layer. One considerable challenge in SDN is to protect against multiple attacks generated by distributed denial of service (DDoS) bots which attempt to make SDN controllers unavailable. The goal of this research is to propose a novel detect and mitigate DDoS attack in SDN controllers using traffic monitoring. Besides the advantages of queueing theory based model is exploited to evaluate the arrival flows and leveraging robust features and entropy, a distance-based classification is designed accurately to detect malicious packets from legitimate packets. The experimental results vividly demonstrate that our proposed detection scheme effectively yields high accuracy as well as high-efficiency controller utilization.
引用
收藏
页码:1985 / 2006
页数:22
相关论文
共 50 条
  • [21] An SVM Based DDoS Attack Detection Method for Ryu SDN Controller
    Mehr, Shideh Yavary
    Ramamurthy, Byrav
    CONEXT'19 COMPANION: PROCEEDINGS OF THE 15TH INTERNATIONAL CONFERENCE ON EMERGING NETWORKING EXPERIMENTS AND TECHNOLOGIES, 2019, : 72 - 73
  • [22] SDN-Based Intrusion Detection System for Early Detection and Mitigation of DDoS Attacks
    Manso, Pedro
    Moura, Jose
    Serrao, Carlos
    INFORMATION, 2019, 10 (03)
  • [23] DDoS attack detection and mitigation using deep neural network in SDN environment
    Hnamte, Vanlalruata
    Najar, Ashfaq Ahmad
    Hong, Nhung-Nguyen
    Hussain, Jamal
    Sugali, Manohar Naik
    COMPUTERS & SECURITY, 2024, 138
  • [24] Detection and mitigation of DDoS attacks based on multi-dimensional characteristics in SDN
    Wang, Kun
    Fu, Yu
    Duan, Xueyuan
    Liu, Taotao
    SCIENTIFIC REPORTS, 2024, 14 (01):
  • [25] FlowTrApp: An SDN Based Architecture for DDoS Attack Detection and Mitigation in Data Centers
    Buragohain, Chaitanya
    Medhi, Nabajyoti
    2016 3RD INTERNATIONAL CONFERENCE ON SIGNAL PROCESSING AND INTEGRATED NETWORKS (SPIN), 2016, : 525 - 530
  • [26] IQR-based approach for DDoS detection and mitigation in SDN附视频
    Rochak Swami
    Mayank Dave
    Virender Ranga
    Defence Technology, 2023, (07) : 76 - 87
  • [27] SDN-based DDoS Attack Mitigation Scheme using Convolution Recursively Enhanced Self Organizing Maps
    Harikrishna, Pillutla
    Amuthan, A.
    SADHANA-ACADEMY PROCEEDINGS IN ENGINEERING SCIENCES, 2020, 45 (01):
  • [28] SDN-based DDoS Attack Mitigation Scheme using Convolution Recursively Enhanced Self Organizing Maps
    Pillutla Harikrishna
    A Amuthan
    Sādhanā, 2020, 45
  • [29] A cooperative DDoS attack detection scheme based on entropy and ensemble learning in SDN
    Shanshan Yu
    Jicheng Zhang
    Ju Liu
    Xiaoqing Zhang
    Yafeng Li
    Tianfeng Xu
    EURASIP Journal on Wireless Communications and Networking, 2021
  • [30] Efficient DDoS attack detection and prevention scheme based on SDN in cloud environment
    He H.
    Hu Y.
    Zheng L.
    Xue Z.
    He, Heng (heheng@wust.edu.cn), 2018, Editorial Board of Journal on Communications (39): : 139 - 151