MARATTO

article · Kafr El-Sheikh Journal of Information Sciences

Cost-Efficient Method for Detecting and Mitigating DDOS Attacks in SDN Based Networks

20231 citationOpen accessKafr el-Sheikh University

Abstract

Software-defined networks (SDN) provide a centralized administration programming interface for managing the network infrastructure. This new approach replaced traditional networks by establishing a flexible connection between the control and data planes, managing network operations through a centralized controller. As a result, prioritizing the security of the SDN controller becomes imperative in SDN networks. In the recent wave of distributed denial-of-service (DDoS) attacks, attackers have shifted their strategy from directly targeting the SDN controller to concentrating on specific links or area, causing disruptions in connectivity. This attack, known as Link-flooding attack (LFA), represent a novel form of DDoS attack. LFA targets the SDN control channel, which transmits control traffic from the SDN controller to switches, taking advantage of shared links in both control and data traffic paths. This sharing exposes a vulnerability that attackers can exploit to disrupt the control channel, using malicious data traffic to execute LFA. Considering the control channel's responsibility for granting centralized control to the controller over each network switch, it becomes relatively easy for an attacker to compromise all network functions. To handle this problem, in this paper, we develop a novel approach based on SDN designed for security solutions against DDoS and LFA. Our proposed scheme utilizes hop-by-hop network measurement to identify and capture abnormal link performance, enabling effective detection of such attacks. Subsequently, a Machine Learning (ML) model is employed to determine whether the congested links indicate the presence of such attacks. Unlike conventional approaches in the literature that solely rely on automatic ML models, our method begins by measuring congestion in each link. If abnormalities are detected, the ML model is then executed to identify whether it is an attack or not. By adopting this approach, we achieve optimized utilization of controller resources. Our proposed scheme will be implemented as an application at the application layer of the Ryu controller. Through our evaluation, we have demonstrated that this approach can efficiently optimize the process of measuring link performance, optimizing the utilization of SDN controller resources, and detecting DDoS and LFA.

Research topics

  • Network Security and Intrusion Detection
  • Software-Defined Networks and 5G
  • Advanced Malware Detection Techniques

Sustainable Development Goals

Read the original research

This page summarises published work. The authoritative version sits with the publisher.

DOI: 10.21608/kjis.2023.251235.1018

Is something wrong with this record? Report it or request removal.

Discussion

Discuss this research

Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.

No discussion yet. Open the first thread.