Cargando…

Adaptive Suspicious Prevention for Defending DoS Attacks in SDN-Based Convergent Networks

The convergent communication network will play an important role as a single platform to unify heterogeneous networks and integrate emerging technologies and existing legacy networks. Although there have been proposed many feasible solutions, they could not become convergent frameworks since they ma...

Descripción completa

Detalles Bibliográficos
Autores principales: Dao, Nhu-Ngoc, Kim, Joongheon, Park, Minho, Cho, Sungrae
Formato: Online Artículo Texto
Lenguaje:English
Publicado: Public Library of Science 2016
Materias:
Acceso en línea:https://www.ncbi.nlm.nih.gov/pmc/articles/PMC4975465/
https://www.ncbi.nlm.nih.gov/pubmed/27494411
http://dx.doi.org/10.1371/journal.pone.0160375
_version_ 1782446731955273728
author Dao, Nhu-Ngoc
Kim, Joongheon
Park, Minho
Cho, Sungrae
author_facet Dao, Nhu-Ngoc
Kim, Joongheon
Park, Minho
Cho, Sungrae
author_sort Dao, Nhu-Ngoc
collection PubMed
description The convergent communication network will play an important role as a single platform to unify heterogeneous networks and integrate emerging technologies and existing legacy networks. Although there have been proposed many feasible solutions, they could not become convergent frameworks since they mainly focused on converting functions between various protocols and interfaces in edge networks, and handling functions for multiple services in core networks, e.g., the Multi-protocol Label Switching (MPLS) technique. Software-defined networking (SDN), on the other hand, is expected to be the ideal future for the convergent network since it can provide a controllable, dynamic, and cost-effective network. However, SDN has an original structural vulnerability behind a lot of advantages, which is the centralized control plane. As the brains of the network, a controller manages the whole network, which is attractive to attackers. In this context, we proposes a novel solution called adaptive suspicious prevention (ASP) mechanism to protect the controller from the Denial of Service (DoS) attacks that could incapacitate an SDN. The ASP is integrated with OpenFlow protocol to detect and prevent DoS attacks effectively. Our comprehensive experimental results show that the ASP enhances the resilience of an SDN network against DoS attacks by up to 38%.
format Online
Article
Text
id pubmed-4975465
institution National Center for Biotechnology Information
language English
publishDate 2016
publisher Public Library of Science
record_format MEDLINE/PubMed
spelling pubmed-49754652016-08-25 Adaptive Suspicious Prevention for Defending DoS Attacks in SDN-Based Convergent Networks Dao, Nhu-Ngoc Kim, Joongheon Park, Minho Cho, Sungrae PLoS One Research Article The convergent communication network will play an important role as a single platform to unify heterogeneous networks and integrate emerging technologies and existing legacy networks. Although there have been proposed many feasible solutions, they could not become convergent frameworks since they mainly focused on converting functions between various protocols and interfaces in edge networks, and handling functions for multiple services in core networks, e.g., the Multi-protocol Label Switching (MPLS) technique. Software-defined networking (SDN), on the other hand, is expected to be the ideal future for the convergent network since it can provide a controllable, dynamic, and cost-effective network. However, SDN has an original structural vulnerability behind a lot of advantages, which is the centralized control plane. As the brains of the network, a controller manages the whole network, which is attractive to attackers. In this context, we proposes a novel solution called adaptive suspicious prevention (ASP) mechanism to protect the controller from the Denial of Service (DoS) attacks that could incapacitate an SDN. The ASP is integrated with OpenFlow protocol to detect and prevent DoS attacks effectively. Our comprehensive experimental results show that the ASP enhances the resilience of an SDN network against DoS attacks by up to 38%. Public Library of Science 2016-08-05 /pmc/articles/PMC4975465/ /pubmed/27494411 http://dx.doi.org/10.1371/journal.pone.0160375 Text en © 2016 Dao et al http://creativecommons.org/licenses/by/4.0/ This is an open access article distributed under the terms of the Creative Commons Attribution License (http://creativecommons.org/licenses/by/4.0/) , which permits unrestricted use, distribution, and reproduction in any medium, provided the original author and source are credited.
spellingShingle Research Article
Dao, Nhu-Ngoc
Kim, Joongheon
Park, Minho
Cho, Sungrae
Adaptive Suspicious Prevention for Defending DoS Attacks in SDN-Based Convergent Networks
title Adaptive Suspicious Prevention for Defending DoS Attacks in SDN-Based Convergent Networks
title_full Adaptive Suspicious Prevention for Defending DoS Attacks in SDN-Based Convergent Networks
title_fullStr Adaptive Suspicious Prevention for Defending DoS Attacks in SDN-Based Convergent Networks
title_full_unstemmed Adaptive Suspicious Prevention for Defending DoS Attacks in SDN-Based Convergent Networks
title_short Adaptive Suspicious Prevention for Defending DoS Attacks in SDN-Based Convergent Networks
title_sort adaptive suspicious prevention for defending dos attacks in sdn-based convergent networks
topic Research Article
url https://www.ncbi.nlm.nih.gov/pmc/articles/PMC4975465/
https://www.ncbi.nlm.nih.gov/pubmed/27494411
http://dx.doi.org/10.1371/journal.pone.0160375
work_keys_str_mv AT daonhungoc adaptivesuspiciouspreventionfordefendingdosattacksinsdnbasedconvergentnetworks
AT kimjoongheon adaptivesuspiciouspreventionfordefendingdosattacksinsdnbasedconvergentnetworks
AT parkminho adaptivesuspiciouspreventionfordefendingdosattacksinsdnbasedconvergentnetworks
AT chosungrae adaptivesuspiciouspreventionfordefendingdosattacksinsdnbasedconvergentnetworks