SDNTruth: Innovative DDoS Detection Scheme for Software-Defined Networks (SDN)


연구 분야: Networking



학회: Journal of Network and Systems Management


초록

Software-Defined Networks (SDN) are a trending technology in the modern Internet by splitting control and data planes and using a central controller. An SDN controller provides flexible flow management at wire-speed packet forwarding in the Internet. The centralized control allows to implement detection and mitigation of security attacks inside the SDN controller. Typically, Distributed Denial of Service (DDoS) attacks pose an immense threat to Internet security. However, the prediction and prevention of DDoS attacks in SDN environments are a huge challenge. In this paper, we introduce a mechanism to mitigate DDoS attacks in SDN using statistical analysis and traffic entropy. To validate the proposal, a prototype was built in the Mininet tool. The accuracy and training time were compared against different Machine Learning algorithms. Finally, we expound on the effectiveness and limitation of the proposed solution as well as show our research plans and further research opportunities.


Author Profile
Tiago Linhares

Computer Science Program Universidade Estadual do Ceará (UECE) Av Dr Silas Munguba 1700 Fortaleza CE 60.714-903 Brazil

Brazil
Author Profile
Ahmed Patel

Computer Science Program Universidade Estadual do Ceará (UECE) Av Dr Silas Munguba 1700 Fortaleza CE 60.714-903 Brazil

Brazil
Author Profile
Ana Luiza Barros

Computer Science Program Universidade Estadual do Ceará (UECE) Av Dr Silas Munguba 1700 Fortaleza CE 60.714-903 Brazil

Brazil

📄 논문 정보

발행 연도 2023년
인용수 27
출판 국가 Brazil
사이트 Springer
좋아요 수 0

연관 논문 목록 (404건)