Cargando…

DoSGuard: Mitigating Denial-of-Service Attacks in Software-Defined Networks

Software-defined networking (SDN) is a new networking paradigm that realizes the fast management and optimal configuration of network resources by decoupling control logic and forwarding functions. However, centralized network architecture brings new security problems, and denial-of-service (DoS) at...

Descripción completa

Detalles Bibliográficos
Autores principales: Li, Jishuai, Tu, Tengfei, Li, Yongsheng, Qin, Sujuan, Shi, Yijie, Wen, Qiaoyan
Formato: Online Artículo Texto
Lenguaje:English
Publicado: MDPI 2022
Materias:
Acceso en línea:https://www.ncbi.nlm.nih.gov/pmc/articles/PMC8840592/
https://www.ncbi.nlm.nih.gov/pubmed/35161800
http://dx.doi.org/10.3390/s22031061
_version_ 1784650658260975616
author Li, Jishuai
Tu, Tengfei
Li, Yongsheng
Qin, Sujuan
Shi, Yijie
Wen, Qiaoyan
author_facet Li, Jishuai
Tu, Tengfei
Li, Yongsheng
Qin, Sujuan
Shi, Yijie
Wen, Qiaoyan
author_sort Li, Jishuai
collection PubMed
description Software-defined networking (SDN) is a new networking paradigm that realizes the fast management and optimal configuration of network resources by decoupling control logic and forwarding functions. However, centralized network architecture brings new security problems, and denial-of-service (DoS) attacks are among the most critical threats. Due to the lack of an effective message-verification mechanism in SDN, attackers can easily launch a DoS attack by faking the source address information. This paper presents DoSGuard, an efficient and protocol-independent defense framework for SDN networks to detect and mitigate such attacks. DoSGuard is a lightweight extension module on SDN controllers that mainly consists of three key components: a monitor, a detector, and a mitigator. The monitor maintains the information between the switches and the hosts for anomaly detection. The detector utilizes OpenFlow message and flow features to detect the attack. The mitigator protects networks by filtering malicious packets. We implement a prototype of DoSGuard in the floodlight controller and evaluate its effectiveness in a simulation environment. Experimental results show the DoSGuard achieves 98.72% detecion precision, and the average CPU utilization of the controller is only around 8%. The results demonstrate that DoSGuard can effectively mitigate DoS attacks against SDN with limited overhead.
format Online
Article
Text
id pubmed-8840592
institution National Center for Biotechnology Information
language English
publishDate 2022
publisher MDPI
record_format MEDLINE/PubMed
spelling pubmed-88405922022-02-13 DoSGuard: Mitigating Denial-of-Service Attacks in Software-Defined Networks Li, Jishuai Tu, Tengfei Li, Yongsheng Qin, Sujuan Shi, Yijie Wen, Qiaoyan Sensors (Basel) Article Software-defined networking (SDN) is a new networking paradigm that realizes the fast management and optimal configuration of network resources by decoupling control logic and forwarding functions. However, centralized network architecture brings new security problems, and denial-of-service (DoS) attacks are among the most critical threats. Due to the lack of an effective message-verification mechanism in SDN, attackers can easily launch a DoS attack by faking the source address information. This paper presents DoSGuard, an efficient and protocol-independent defense framework for SDN networks to detect and mitigate such attacks. DoSGuard is a lightweight extension module on SDN controllers that mainly consists of three key components: a monitor, a detector, and a mitigator. The monitor maintains the information between the switches and the hosts for anomaly detection. The detector utilizes OpenFlow message and flow features to detect the attack. The mitigator protects networks by filtering malicious packets. We implement a prototype of DoSGuard in the floodlight controller and evaluate its effectiveness in a simulation environment. Experimental results show the DoSGuard achieves 98.72% detecion precision, and the average CPU utilization of the controller is only around 8%. The results demonstrate that DoSGuard can effectively mitigate DoS attacks against SDN with limited overhead. MDPI 2022-01-29 /pmc/articles/PMC8840592/ /pubmed/35161800 http://dx.doi.org/10.3390/s22031061 Text en © 2022 by the authors. https://creativecommons.org/licenses/by/4.0/Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (https://creativecommons.org/licenses/by/4.0/).
spellingShingle Article
Li, Jishuai
Tu, Tengfei
Li, Yongsheng
Qin, Sujuan
Shi, Yijie
Wen, Qiaoyan
DoSGuard: Mitigating Denial-of-Service Attacks in Software-Defined Networks
title DoSGuard: Mitigating Denial-of-Service Attacks in Software-Defined Networks
title_full DoSGuard: Mitigating Denial-of-Service Attacks in Software-Defined Networks
title_fullStr DoSGuard: Mitigating Denial-of-Service Attacks in Software-Defined Networks
title_full_unstemmed DoSGuard: Mitigating Denial-of-Service Attacks in Software-Defined Networks
title_short DoSGuard: Mitigating Denial-of-Service Attacks in Software-Defined Networks
title_sort dosguard: mitigating denial-of-service attacks in software-defined networks
topic Article
url https://www.ncbi.nlm.nih.gov/pmc/articles/PMC8840592/
https://www.ncbi.nlm.nih.gov/pubmed/35161800
http://dx.doi.org/10.3390/s22031061
work_keys_str_mv AT lijishuai dosguardmitigatingdenialofserviceattacksinsoftwaredefinednetworks
AT tutengfei dosguardmitigatingdenialofserviceattacksinsoftwaredefinednetworks
AT liyongsheng dosguardmitigatingdenialofserviceattacksinsoftwaredefinednetworks
AT qinsujuan dosguardmitigatingdenialofserviceattacksinsoftwaredefinednetworks
AT shiyijie dosguardmitigatingdenialofserviceattacksinsoftwaredefinednetworks
AT wenqiaoyan dosguardmitigatingdenialofserviceattacksinsoftwaredefinednetworks