Affiliation:
1. College of Computer Science and Technology, Zhejiang University of Technology, Hangzhou 310023, China
2. School of Mathematics, Zhengzhou University of Aeronautics, Zhengzhou 450046, China
Abstract
Software defined networking (SDN) improves the flexibility and programmability of the network by separating the control plane and the data plane and effectively realizes the global control of the network infrastructure. However, the centralized structure design of SDN exposes the controller to potential threats. Attackers have used the active flow table delivery mode to launch distributed denial of service (DDoS) attacks on the SDN controller, resulting in the controller failure and seriously affecting the network performance. To overcome this problem, this paper proposes a defense framework called CC-Guard. The framework consists of four modules: attack detection triggering, switch migration, anomaly detection, and mitigation. Among them, the attack detection trigger module improves the system’s timely response to DDoS attacks. The switch migration module effectively unclogs the controller congestion problem and provides convenience for network flow transmission. The anomaly detection module uses a coarse-grained method for two-stage detection, which improves the detection accuracy. The mitigation module uses the idea of cross-domain cooperation of the controller to clear the abnormal flow in the blacklist. Experimental results show that our proposed CC-Guard has real-time DDoS attack defense capability and high detection accuracy, as well as efficient network resource utilization.
Subject
General Physics and Astronomy
Reference32 articles.
1. SDN/NFV-Based Mobile Packet Core Network Architectures: A Survey;Nguyen;IEEE Commun. Surv. Tutor.,2017
2. A Policy-Based Security Architecture for Software Defined Networks;Varadharajan;IEEE Trans. Inf. Forensics Secur.,2019
3. Bera, P., Saha, A., and Setua, S. (2016, January 10–11). Denial of Service Attack in Software Defined Network. Proceedings of the 5th International Conference on Computer Science and Network Technology (ICSNT), Changchun, China.
4. (2022, September 11). OpenFlow Switch Specifification V1.4.0. Available online: https://www.opennetworking.org/wp-content/uploads/2014/10/openflow-spec-v1.4.0.pdf.
5. 1D convolutional neural networks and applications: A survey;Kiranyaz;Mech. Syst. Signal Process.,2021
Cited by
4 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献