TFAD: TCP flooding attack detection in software-defined networking using proxy-based and machine learning-based mechanisms


연구 분야: Networking



학회: Cluster Computing


초록

Software-defined networks (SDN) offer a centralized administration programming interface to govern the network infrastructure. It overtook conventional networks by creating a configurable link between the control and data planes. As the logic of the SDN environment completely depends on the control plane, the controller is vulnerable to many security attacks. To degrade the network’s performance, attackers will saturate the control plane resources. TCP flooding is a serious threat in which attackers restrict legitimate users from accessing the network resources. To handle this problem, we propose a TCP Flooding Attack Detection (TFAD) technique using proxy-based and Machine-Learning-based mechanisms (ML-TFAD). The TFAD technique contains two proxies, SYN and ACK: the former defends against TCP SYN flood attacks and the latter against TCP ACK flood attacks. The ML-TFAD module uses the C4.5 decision tree algorithm, which detects SYN flood attacks before reaching the targeted server. The CAIDA 2007 DDoS dataset is involved in training the proposed model. The proposed mechanisms help remove half-opened connections from the server queue at the earliest to accommodate TCP connection requests from legitimate users.


Author Profile
K. Muthamil Sudar

Department of Computer Science and Engineering Mepco Schlenk Engineering College Sivakasi Tamil Nadu 626005 India

Andorra
Author Profile
P. Deepalakshmi

Department of Computer Science and Engineering School of Computing Kalasalingam Academy of Research and Education Krishnankoil Tamil Nadu 626126 India

Andorra
Author Profile
Ashish Singh

School of Computer Engineering Kalinga Institute of Industrial Technology (KIIT) Deemed to be University (An Institute of Eminence) Bhubhaneswar Odisha 751024 India

Belgium

📄 논문 정보

발행 연도 2022년
인용수 25
출판 국가 Andorra, Belgium
사이트 Springer
좋아요 수 0

연관 논문 목록 (46건)