A Method of DDoS Attack Detection and Mitigation for the Comprehensive Coordinated Protection of SDN Controllers

Author:

Wang Jin1,Wang Liping1,Wang Ruiqing2

Affiliation:

1. College of Computer Science and Technology, Zhejiang University of Technology, Hangzhou 310023, China

2. School of Mathematics, Zhengzhou University of Aeronautics, Zhengzhou 450046, China

Abstract

Software defined networking (SDN) improves the flexibility and programmability of the network by separating the control plane and the data plane and effectively realizes the global control of the network infrastructure. However, the centralized structure design of SDN exposes the controller to potential threats. Attackers have used the active flow table delivery mode to launch distributed denial of service (DDoS) attacks on the SDN controller, resulting in the controller failure and seriously affecting the network performance. To overcome this problem, this paper proposes a defense framework called CC-Guard. The framework consists of four modules: attack detection triggering, switch migration, anomaly detection, and mitigation. Among them, the attack detection trigger module improves the system’s timely response to DDoS attacks. The switch migration module effectively unclogs the controller congestion problem and provides convenience for network flow transmission. The anomaly detection module uses a coarse-grained method for two-stage detection, which improves the detection accuracy. The mitigation module uses the idea of cross-domain cooperation of the controller to clear the abnormal flow in the blacklist. Experimental results show that our proposed CC-Guard has real-time DDoS attack defense capability and high detection accuracy, as well as efficient network resource utilization.

Publisher

MDPI AG

Subject

General Physics and Astronomy

Reference32 articles.

1. SDN/NFV-Based Mobile Packet Core Network Architectures: A Survey;Nguyen;IEEE Commun. Surv. Tutor.,2017

2. A Policy-Based Security Architecture for Software Defined Networks;Varadharajan;IEEE Trans. Inf. Forensics Secur.,2019

3. Bera, P., Saha, A., and Setua, S. (2016, January 10–11). Denial of Service Attack in Software Defined Network. Proceedings of the 5th International Conference on Computer Science and Network Technology (ICSNT), Changchun, China.

4. (2022, September 11). OpenFlow Switch Specifification V1.4.0. Available online: https://www.opennetworking.org/wp-content/uploads/2014/10/openflow-spec-v1.4.0.pdf.

5. 1D convolutional neural networks and applications: A survey;Kiranyaz;Mech. Syst. Signal Process.,2021

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3