Affiliation:
1. Department of Computer Engineering, Gazi University, Turkey
Abstract
Despite many advantages of software defined networking (SDN) such as manageability, scalability, and performance, it has inherent security threats. In particular, denial of service (DoS) attacks are major threats to SDN. The controller’s processing and communication abilities are overwhelmed by DoS attacks. The capacity of the flow tables in the switching device is exhausted due to excess flows created by the controller because of malicious packets. DoS attacks on the controller cause the network performance to drop to a critical level. In this paper, a new SDN controller component was proposed to detect and mitigate DoS attacks in the SDN controller. POX layer three controller component was used for underlying a testbed for PacketIn messages. Any packet from the host was incremented to measure the rate of packet according to its device identification and its input port number. Considering the rate of packets received by the controller and threshold set, malicious packets could be detected and mitigated easily. A developed controller component was tested in a Mininet simulation environment with an hping3 tool to build artificial DoS attacks. Using the enhanced controller component, DoS packets were prevented from accessing the controller and thus, the data plane (switching devices) was prevented from being filled with unwanted flows.
Publisher
UUM Press, Universiti Utara Malaysia
Subject
General Mathematics,General Computer Science
Reference32 articles.
1. A survey of securing networks using software defined networking;Ali;IEEE transactions on reliability 64(3) 1086-1097 https,2015
2. on Hot topics in software defined networking (pp. 151-152). Hong Kong, China: ACM. https://doi.org/10.1145/2491185.2491222
3. Bholebawa, I. Z., & Dalal, U. D. (2016). Design and performance analysis of OpenFlow-enabled network topologies using Mininet. International Journal of Computer and Communication Engineering, 5(6), 419. https://doi.org/10.17706/IJCCE.2016.5.6.419-429
4. Cabaj, K., Wytrebowicz, J., Kuklinski, S., Radziszewski, P., & Dinh, K. T. (2014). SDN architecture impact on network security. In M. Ganzha, L. Maciaszek, M. Paprzycki (Eds.), Federated Conference on Computer Science and Information Systems (FedCSIS) (pp. 143-148). Warsaw, Poland: ACSIS. https://doi.org/10.15439/2014F473
5. Cui, Y., Yan, L., Li, S., Xing, H., Pan, W., Zhu, J., & Zheng, X. (2016). SD-
Cited by
1 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献