A Statistical Model for Early Detection of DDoS Attacks on Random Targets in SDN

被引:0
|
作者
Reza Bakhtiari Shohani
Seyedakbar Mostafavi
Vesal Hakami
机构
[1] Yazd University,Department of Computer Engineering
[2] Iran University of Science and Technology,Center of Excellence in Future Networks, School of Computer Engineering
来源
关键词
Distributed denial of service attack; Software-defined networks; Attack detection; Linear regression;
D O I
暂无
中图分类号
学科分类号
摘要
Software Defined Networks (SDNs) have accelerated and simplified the management, configuration and error detection in today’s networking systems. However, SDN is prone to some new security threats, the most important of which is its vulnerability to a new generation of Distributed Denial of Service (DDoS) attack in which fake packets target random destinations instead of targeting a single server. In this paper, we show that the existing early detection methods such as entropy- and principal component analysis (PCA)-based methods are not sufficiently capable of detecting this type of attack. Instead, we propose a novel network traffic anomaly detection framework for tackling with DDoS in SDN. Our framework consists of four stages: first, we draw on extensive experiments on an SDN test-bed to analyze the behavior of normal and attack traffic. Second, a statistical trapezoid model is proposed to estimate the number of table misses in the controller. Third, we estimate the threshold of the table misses in regular time intervals using linear regression together with EWMA estimation. In the last stage, we use the derived model as a reference to detect DDoS attacks as anomalous deviations. The evaluation results demonstrate that using this method, one can detect DDoS attacks against an SDN-based network in its early stages, with few false positives, and regardless of the specifics of the attack.
引用
收藏
页码:379 / 400
页数:21
相关论文
共 50 条
  • [1] A Statistical Model for Early Detection of DDoS Attacks on Random Targets in SDN
    Shohani, Reza Bakhtiari
    Mostafavi, Seyedakbar
    Hakami, Vesal
    WIRELESS PERSONAL COMMUNICATIONS, 2021, 120 (01) : 379 - 400
  • [2] Early Detection of DDoS Attacks against SDN Controllers
    Mousavi, Seyed Mohammad
    St-Hilaire, Marc
    2015 INTERNATIONAL CONFERENCE ON COMPUTING, NETWORKING AND COMMUNICATIONS (ICNC), 2015, : 77 - 81
  • [3] The DDoS attacks detection through machine learning and statistical methods in SDN
    Afsaneh Banitalebi Dehkordi
    MohammadReza Soltanaghaei
    Farsad Zamani Boroujeni
    The Journal of Supercomputing, 2021, 77 : 2383 - 2415
  • [4] The DDoS attacks detection through machine learning and statistical methods in SDN
    Dehkordi, Afsaneh Banitalebi
    Soltanaghaei, MohammadReza
    Boroujeni, Farsad Zamani
    JOURNAL OF SUPERCOMPUTING, 2021, 77 (03): : 2383 - 2415
  • [5] Modeling DDOS attacks in sdn and detection using random forest classifier
    Abdullahi Wabi, Aishatu
    Idris, Ismail
    Mikail Olaniyi, Olayemi
    Joseph, A.
    Surajudeen Adebayo, Olawale
    Journal of Cyber Security Technology, 2024, 8 (04) : 229 - 242
  • [6] An integrated SDN framework for early detection of DDoS attacks in cloud computing
    Songa, Asha Varma
    Karri, Ganesh Reddy
    JOURNAL OF CLOUD COMPUTING-ADVANCES SYSTEMS AND APPLICATIONS, 2024, 13 (01):
  • [7] An integrated SDN framework for early detection of DDoS attacks in cloud computing
    Asha Varma Songa
    Ganesh Reddy Karri
    Journal of Cloud Computing, 13
  • [8] Real-Time Detection of DDoS Attacks Based on Random Forest in SDN
    Ma, Ruikui
    Wang, Qiuqian
    Bu, Xiangxi
    Chen, Xuebin
    APPLIED SCIENCES-BASEL, 2023, 13 (13):
  • [9] SDN-Based Intrusion Detection System for Early Detection and Mitigation of DDoS Attacks
    Manso, Pedro
    Moura, Jose
    Serrao, Carlos
    INFORMATION, 2019, 10 (03)
  • [10] An RBF-PSO Based Approach for Early Detection of DDoS Attacks in SDN
    Dayal, Neelam
    Srivastava, Shashank
    2018 10TH INTERNATIONAL CONFERENCE ON COMMUNICATION SYSTEMS & NETWORKS (COMSNETS), 2018, : 17 - 24