Cargando…

A Method of DDoS Attack Detection and Mitigation for the Comprehensive Coordinated Protection of SDN Controllers

Software defined networking (SDN) improves the flexibility and programmability of the network by separating the control plane and the data plane and effectively realizes the global control of the network infrastructure. However, the centralized structure design of SDN exposes the controller to poten...

Descripción completa

Detalles Bibliográficos
Autores principales: Wang, Jin, Wang, Liping, Wang, Ruiqing
Formato: Online Artículo Texto
Lenguaje:English
Publicado: MDPI 2023
Materias:
Acceso en línea:https://www.ncbi.nlm.nih.gov/pmc/articles/PMC10453536/
https://www.ncbi.nlm.nih.gov/pubmed/37628240
http://dx.doi.org/10.3390/e25081210
_version_ 1785095961276579840
author Wang, Jin
Wang, Liping
Wang, Ruiqing
author_facet Wang, Jin
Wang, Liping
Wang, Ruiqing
author_sort Wang, Jin
collection PubMed
description Software defined networking (SDN) improves the flexibility and programmability of the network by separating the control plane and the data plane and effectively realizes the global control of the network infrastructure. However, the centralized structure design of SDN exposes the controller to potential threats. Attackers have used the active flow table delivery mode to launch distributed denial of service (DDoS) attacks on the SDN controller, resulting in the controller failure and seriously affecting the network performance. To overcome this problem, this paper proposes a defense framework called CC-Guard. The framework consists of four modules: attack detection triggering, switch migration, anomaly detection, and mitigation. Among them, the attack detection trigger module improves the system’s timely response to DDoS attacks. The switch migration module effectively unclogs the controller congestion problem and provides convenience for network flow transmission. The anomaly detection module uses a coarse-grained method for two-stage detection, which improves the detection accuracy. The mitigation module uses the idea of cross-domain cooperation of the controller to clear the abnormal flow in the blacklist. Experimental results show that our proposed CC-Guard has real-time DDoS attack defense capability and high detection accuracy, as well as efficient network resource utilization.
format Online
Article
Text
id pubmed-10453536
institution National Center for Biotechnology Information
language English
publishDate 2023
publisher MDPI
record_format MEDLINE/PubMed
spelling pubmed-104535362023-08-26 A Method of DDoS Attack Detection and Mitigation for the Comprehensive Coordinated Protection of SDN Controllers Wang, Jin Wang, Liping Wang, Ruiqing Entropy (Basel) Article Software defined networking (SDN) improves the flexibility and programmability of the network by separating the control plane and the data plane and effectively realizes the global control of the network infrastructure. However, the centralized structure design of SDN exposes the controller to potential threats. Attackers have used the active flow table delivery mode to launch distributed denial of service (DDoS) attacks on the SDN controller, resulting in the controller failure and seriously affecting the network performance. To overcome this problem, this paper proposes a defense framework called CC-Guard. The framework consists of four modules: attack detection triggering, switch migration, anomaly detection, and mitigation. Among them, the attack detection trigger module improves the system’s timely response to DDoS attacks. The switch migration module effectively unclogs the controller congestion problem and provides convenience for network flow transmission. The anomaly detection module uses a coarse-grained method for two-stage detection, which improves the detection accuracy. The mitigation module uses the idea of cross-domain cooperation of the controller to clear the abnormal flow in the blacklist. Experimental results show that our proposed CC-Guard has real-time DDoS attack defense capability and high detection accuracy, as well as efficient network resource utilization. MDPI 2023-08-14 /pmc/articles/PMC10453536/ /pubmed/37628240 http://dx.doi.org/10.3390/e25081210 Text en © 2023 by the authors. https://creativecommons.org/licenses/by/4.0/Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (https://creativecommons.org/licenses/by/4.0/).
spellingShingle Article
Wang, Jin
Wang, Liping
Wang, Ruiqing
A Method of DDoS Attack Detection and Mitigation for the Comprehensive Coordinated Protection of SDN Controllers
title A Method of DDoS Attack Detection and Mitigation for the Comprehensive Coordinated Protection of SDN Controllers
title_full A Method of DDoS Attack Detection and Mitigation for the Comprehensive Coordinated Protection of SDN Controllers
title_fullStr A Method of DDoS Attack Detection and Mitigation for the Comprehensive Coordinated Protection of SDN Controllers
title_full_unstemmed A Method of DDoS Attack Detection and Mitigation for the Comprehensive Coordinated Protection of SDN Controllers
title_short A Method of DDoS Attack Detection and Mitigation for the Comprehensive Coordinated Protection of SDN Controllers
title_sort method of ddos attack detection and mitigation for the comprehensive coordinated protection of sdn controllers
topic Article
url https://www.ncbi.nlm.nih.gov/pmc/articles/PMC10453536/
https://www.ncbi.nlm.nih.gov/pubmed/37628240
http://dx.doi.org/10.3390/e25081210
work_keys_str_mv AT wangjin amethodofddosattackdetectionandmitigationforthecomprehensivecoordinatedprotectionofsdncontrollers
AT wangliping amethodofddosattackdetectionandmitigationforthecomprehensivecoordinatedprotectionofsdncontrollers
AT wangruiqing amethodofddosattackdetectionandmitigationforthecomprehensivecoordinatedprotectionofsdncontrollers
AT wangjin methodofddosattackdetectionandmitigationforthecomprehensivecoordinatedprotectionofsdncontrollers
AT wangliping methodofddosattackdetectionandmitigationforthecomprehensivecoordinatedprotectionofsdncontrollers
AT wangruiqing methodofddosattackdetectionandmitigationforthecomprehensivecoordinatedprotectionofsdncontrollers