Cargando…
Adaptive Suspicious Prevention for Defending DoS Attacks in SDN-Based Convergent Networks
The convergent communication network will play an important role as a single platform to unify heterogeneous networks and integrate emerging technologies and existing legacy networks. Although there have been proposed many feasible solutions, they could not become convergent frameworks since they ma...
Autores principales: | , , , |
---|---|
Formato: | Online Artículo Texto |
Lenguaje: | English |
Publicado: |
Public Library of Science
2016
|
Materias: | |
Acceso en línea: | https://www.ncbi.nlm.nih.gov/pmc/articles/PMC4975465/ https://www.ncbi.nlm.nih.gov/pubmed/27494411 http://dx.doi.org/10.1371/journal.pone.0160375 |
_version_ | 1782446731955273728 |
---|---|
author | Dao, Nhu-Ngoc Kim, Joongheon Park, Minho Cho, Sungrae |
author_facet | Dao, Nhu-Ngoc Kim, Joongheon Park, Minho Cho, Sungrae |
author_sort | Dao, Nhu-Ngoc |
collection | PubMed |
description | The convergent communication network will play an important role as a single platform to unify heterogeneous networks and integrate emerging technologies and existing legacy networks. Although there have been proposed many feasible solutions, they could not become convergent frameworks since they mainly focused on converting functions between various protocols and interfaces in edge networks, and handling functions for multiple services in core networks, e.g., the Multi-protocol Label Switching (MPLS) technique. Software-defined networking (SDN), on the other hand, is expected to be the ideal future for the convergent network since it can provide a controllable, dynamic, and cost-effective network. However, SDN has an original structural vulnerability behind a lot of advantages, which is the centralized control plane. As the brains of the network, a controller manages the whole network, which is attractive to attackers. In this context, we proposes a novel solution called adaptive suspicious prevention (ASP) mechanism to protect the controller from the Denial of Service (DoS) attacks that could incapacitate an SDN. The ASP is integrated with OpenFlow protocol to detect and prevent DoS attacks effectively. Our comprehensive experimental results show that the ASP enhances the resilience of an SDN network against DoS attacks by up to 38%. |
format | Online Article Text |
id | pubmed-4975465 |
institution | National Center for Biotechnology Information |
language | English |
publishDate | 2016 |
publisher | Public Library of Science |
record_format | MEDLINE/PubMed |
spelling | pubmed-49754652016-08-25 Adaptive Suspicious Prevention for Defending DoS Attacks in SDN-Based Convergent Networks Dao, Nhu-Ngoc Kim, Joongheon Park, Minho Cho, Sungrae PLoS One Research Article The convergent communication network will play an important role as a single platform to unify heterogeneous networks and integrate emerging technologies and existing legacy networks. Although there have been proposed many feasible solutions, they could not become convergent frameworks since they mainly focused on converting functions between various protocols and interfaces in edge networks, and handling functions for multiple services in core networks, e.g., the Multi-protocol Label Switching (MPLS) technique. Software-defined networking (SDN), on the other hand, is expected to be the ideal future for the convergent network since it can provide a controllable, dynamic, and cost-effective network. However, SDN has an original structural vulnerability behind a lot of advantages, which is the centralized control plane. As the brains of the network, a controller manages the whole network, which is attractive to attackers. In this context, we proposes a novel solution called adaptive suspicious prevention (ASP) mechanism to protect the controller from the Denial of Service (DoS) attacks that could incapacitate an SDN. The ASP is integrated with OpenFlow protocol to detect and prevent DoS attacks effectively. Our comprehensive experimental results show that the ASP enhances the resilience of an SDN network against DoS attacks by up to 38%. Public Library of Science 2016-08-05 /pmc/articles/PMC4975465/ /pubmed/27494411 http://dx.doi.org/10.1371/journal.pone.0160375 Text en © 2016 Dao et al http://creativecommons.org/licenses/by/4.0/ This is an open access article distributed under the terms of the Creative Commons Attribution License (http://creativecommons.org/licenses/by/4.0/) , which permits unrestricted use, distribution, and reproduction in any medium, provided the original author and source are credited. |
spellingShingle | Research Article Dao, Nhu-Ngoc Kim, Joongheon Park, Minho Cho, Sungrae Adaptive Suspicious Prevention for Defending DoS Attacks in SDN-Based Convergent Networks |
title | Adaptive Suspicious Prevention for Defending DoS Attacks in SDN-Based Convergent Networks |
title_full | Adaptive Suspicious Prevention for Defending DoS Attacks in SDN-Based Convergent Networks |
title_fullStr | Adaptive Suspicious Prevention for Defending DoS Attacks in SDN-Based Convergent Networks |
title_full_unstemmed | Adaptive Suspicious Prevention for Defending DoS Attacks in SDN-Based Convergent Networks |
title_short | Adaptive Suspicious Prevention for Defending DoS Attacks in SDN-Based Convergent Networks |
title_sort | adaptive suspicious prevention for defending dos attacks in sdn-based convergent networks |
topic | Research Article |
url | https://www.ncbi.nlm.nih.gov/pmc/articles/PMC4975465/ https://www.ncbi.nlm.nih.gov/pubmed/27494411 http://dx.doi.org/10.1371/journal.pone.0160375 |
work_keys_str_mv | AT daonhungoc adaptivesuspiciouspreventionfordefendingdosattacksinsdnbasedconvergentnetworks AT kimjoongheon adaptivesuspiciouspreventionfordefendingdosattacksinsdnbasedconvergentnetworks AT parkminho adaptivesuspiciouspreventionfordefendingdosattacksinsdnbasedconvergentnetworks AT chosungrae adaptivesuspiciouspreventionfordefendingdosattacksinsdnbasedconvergentnetworks |