A Statistical Model for Early Detection of DDoS Attacks on Random Targets in SDN

被引:0
|
作者
Reza Bakhtiari Shohani
Seyedakbar Mostafavi
Vesal Hakami
机构
[1] Yazd University,Department of Computer Engineering
[2] Iran University of Science and Technology,Center of Excellence in Future Networks, School of Computer Engineering
来源
关键词
Distributed denial of service attack; Software-defined networks; Attack detection; Linear regression;
D O I
暂无
中图分类号
学科分类号
摘要
Software Defined Networks (SDNs) have accelerated and simplified the management, configuration and error detection in today’s networking systems. However, SDN is prone to some new security threats, the most important of which is its vulnerability to a new generation of Distributed Denial of Service (DDoS) attack in which fake packets target random destinations instead of targeting a single server. In this paper, we show that the existing early detection methods such as entropy- and principal component analysis (PCA)-based methods are not sufficiently capable of detecting this type of attack. Instead, we propose a novel network traffic anomaly detection framework for tackling with DDoS in SDN. Our framework consists of four stages: first, we draw on extensive experiments on an SDN test-bed to analyze the behavior of normal and attack traffic. Second, a statistical trapezoid model is proposed to estimate the number of table misses in the controller. Third, we estimate the threshold of the table misses in regular time intervals using linear regression together with EWMA estimation. In the last stage, we use the derived model as a reference to detect DDoS attacks as anomalous deviations. The evaluation results demonstrate that using this method, one can detect DDoS attacks against an SDN-based network in its early stages, with few false positives, and regardless of the specifics of the attack.
引用
收藏
页码:379 / 400
页数:21
相关论文
共 50 条
  • [31] A Novel Statistical Technique for Detection of DDoS Attacks in KDD Dataset
    Kaur, Gagandeep
    Varma, Suyash
    Jain, Arpit
    2013 SIXTH INTERNATIONAL CONFERENCE ON CONTEMPORARY COMPUTING (IC3), 2013, : 393 - 398
  • [32] Statistical Properties of DDoS Attacks
    Erhan, Derya
    Anarim, Emin
    2019 6TH INTERNATIONAL CONFERENCE ON CONTROL, DECISION AND INFORMATION TECHNOLOGIES (CODIT 2019), 2019, : 1238 - 1242
  • [33] Detection of DNS DDoS Attacks with Random Forest Algorithm on Spark
    Chen, Liguo
    Zhang, Yuedong
    Zhao, Qi
    Geng, Guanggang
    Yan, ZhiWei
    15TH INTERNATIONAL CONFERENCE ON MOBILE SYSTEMS AND PERVASIVE COMPUTING (MOBISPC 2018) / THE 13TH INTERNATIONAL CONFERENCE ON FUTURE NETWORKS AND COMMUNICATIONS (FNC-2018) / AFFILIATED WORKSHOPS, 2018, 134 : 310 - 315
  • [34] Detection and mitigation of DDoS in SDN
    Pande, Bhavika
    Bhagat, Gargi
    Priya, Shanu
    Agrawal, Himanshu
    2018 ELEVENTH INTERNATIONAL CONFERENCE ON CONTEMPORARY COMPUTING (IC3), 2018, : 371 - 373
  • [35] One-Dimensional Convolutional Neural Network for Detection and Mitigation of DDoS Attacks in SDN
    Alshra'a, Abdullah
    Jochen, Seitz
    MACHINE LEARNING FOR NETWORKING, MLN 2021, 2022, 13175 : 11 - 28
  • [36] Detection and mitigation of DDoS attacks in SDN: A comprehensive review, research challenges and future directions
    Singh, Jagdeep
    Behal, Sunny
    COMPUTER SCIENCE REVIEW, 2020, 37
  • [37] Neural Network-Based Approach for Detection and Mitigation of DDoS Attacks in SDN Environments
    Hannache, Oussama
    Batouche, Mohamed Chaouki
    INTERNATIONAL JOURNAL OF INFORMATION SECURITY AND PRIVACY, 2020, 14 (03) : 50 - 71
  • [38] Adversarial Deep Learning approach detection and defense against DDoS attacks in SDN environments
    Novaes, Matheus P.
    Carvalho, Luiz F.
    Lloret, Jaime
    Proenca, Mario Lemes, Jr.
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2021, 125 : 156 - 167
  • [39] SDN Based Collaborative Scheme for Mitigation of DDoS Attacks
    Hameed, Sufian
    Khan, Hassan Ahmed
    FUTURE INTERNET, 2018, 10 (03)
  • [40] A Method for DDoS Attacks Prevention Using SDN and NFV
    Shayegan, Mohammad Javad
    Damghanian, Amirreza
    IEEE ACCESS, 2024, 12 : 108176 - 108184