A Statistical Model for Early Detection of DDoS Attacks on Random Targets in SDN

被引:0
|
作者
Reza Bakhtiari Shohani
Seyedakbar Mostafavi
Vesal Hakami
机构
[1] Yazd University,Department of Computer Engineering
[2] Iran University of Science and Technology,Center of Excellence in Future Networks, School of Computer Engineering
来源
关键词
Distributed denial of service attack; Software-defined networks; Attack detection; Linear regression;
D O I
暂无
中图分类号
学科分类号
摘要
Software Defined Networks (SDNs) have accelerated and simplified the management, configuration and error detection in today’s networking systems. However, SDN is prone to some new security threats, the most important of which is its vulnerability to a new generation of Distributed Denial of Service (DDoS) attack in which fake packets target random destinations instead of targeting a single server. In this paper, we show that the existing early detection methods such as entropy- and principal component analysis (PCA)-based methods are not sufficiently capable of detecting this type of attack. Instead, we propose a novel network traffic anomaly detection framework for tackling with DDoS in SDN. Our framework consists of four stages: first, we draw on extensive experiments on an SDN test-bed to analyze the behavior of normal and attack traffic. Second, a statistical trapezoid model is proposed to estimate the number of table misses in the controller. Third, we estimate the threshold of the table misses in regular time intervals using linear regression together with EWMA estimation. In the last stage, we use the derived model as a reference to detect DDoS attacks as anomalous deviations. The evaluation results demonstrate that using this method, one can detect DDoS attacks against an SDN-based network in its early stages, with few false positives, and regardless of the specifics of the attack.
引用
收藏
页码:379 / 400
页数:21
相关论文
共 50 条
  • [41] New distributed SDN framework for mitigating DDoS attacks
    Alshehhi A.
    Yeun C.Y.
    Damiani E.
    Transactions of the Korean Institute of Electrical Engineers, 2017, 66 (12): : 1913 - 1920
  • [42] Optimized Artificial Intelligence Model for DDoS Detection in SDN Environment
    Al-Dunainawi, Yousif
    Al-Kaseem, Bilal R.
    Al-Raweshidy, Hamed S.
    IEEE ACCESS, 2023, 11 : 106733 - 106748
  • [43] Machine learning algorithms to detect DDoS attacks in SDN
    Santos, Reneilson
    Souza, Danilo
    Santo, Walter
    Ribeiro, Admilson
    Moreno, Edward
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2020, 32 (16):
  • [44] Adaptive and Predictive SDN Control During DDoS Attacks
    Vempati, Jagannadh
    Dantu, Ram
    Badruddoja, Syed
    Thompson, Mark
    2020 IEEE INTERNATIONAL CONFERENCE ON INTELLIGENCE AND SECURITY INFORMATICS (ISI), 2020, : 104 - 109
  • [45] Strategies for detecting and mitigating DDoS attacks in SDN: A survey
    Joelle, Misenga Mumpela
    Park, Young-Hoon
    JOURNAL OF INTELLIGENT & FUZZY SYSTEMS, 2018, 35 (06) : 5913 - 5925
  • [46] An Efficient IDS Framework for DDoS Attacks in SDN Environment
    Varghese, Josy Elsa
    Muniyal, Balachandra
    IEEE ACCESS, 2021, 9 : 69680 - 69699
  • [47] Defense Mechanisms Against DDoS Attacks in SDN Environment
    Kalkan, Kubra
    Gur, Gurkan
    Alagoz, Fatih
    IEEE COMMUNICATIONS MAGAZINE, 2017, 55 (09) : 175 - 179
  • [49] Detection of DDoS Attacks Against Wireless SDN Controllers Based on the Fuzzy Synthetic Evaluation Decision-making Model
    Yan, Qiao
    Gong, Qingxiang
    Deng, Fang-an
    AD HOC & SENSOR WIRELESS NETWORKS, 2016, 33 (1-4) : 275 - 299
  • [50] On the effectiveness of DDoS attacks on statistical filtering
    Li, QM
    Chang, EC
    Chan, MC
    IEEE INFOCOM 2005: THE CONFERENCE ON COMPUTER COMMUNICATIONS, VOLS 1-4, PROCEEDINGS, 2005, : 1373 - 1383