Cargando…
DoSGuard: Mitigating Denial-of-Service Attacks in Software-Defined Networks
Software-defined networking (SDN) is a new networking paradigm that realizes the fast management and optimal configuration of network resources by decoupling control logic and forwarding functions. However, centralized network architecture brings new security problems, and denial-of-service (DoS) at...
Autores principales: | , , , , , |
---|---|
Formato: | Online Artículo Texto |
Lenguaje: | English |
Publicado: |
MDPI
2022
|
Materias: | |
Acceso en línea: | https://www.ncbi.nlm.nih.gov/pmc/articles/PMC8840592/ https://www.ncbi.nlm.nih.gov/pubmed/35161800 http://dx.doi.org/10.3390/s22031061 |
_version_ | 1784650658260975616 |
---|---|
author | Li, Jishuai Tu, Tengfei Li, Yongsheng Qin, Sujuan Shi, Yijie Wen, Qiaoyan |
author_facet | Li, Jishuai Tu, Tengfei Li, Yongsheng Qin, Sujuan Shi, Yijie Wen, Qiaoyan |
author_sort | Li, Jishuai |
collection | PubMed |
description | Software-defined networking (SDN) is a new networking paradigm that realizes the fast management and optimal configuration of network resources by decoupling control logic and forwarding functions. However, centralized network architecture brings new security problems, and denial-of-service (DoS) attacks are among the most critical threats. Due to the lack of an effective message-verification mechanism in SDN, attackers can easily launch a DoS attack by faking the source address information. This paper presents DoSGuard, an efficient and protocol-independent defense framework for SDN networks to detect and mitigate such attacks. DoSGuard is a lightweight extension module on SDN controllers that mainly consists of three key components: a monitor, a detector, and a mitigator. The monitor maintains the information between the switches and the hosts for anomaly detection. The detector utilizes OpenFlow message and flow features to detect the attack. The mitigator protects networks by filtering malicious packets. We implement a prototype of DoSGuard in the floodlight controller and evaluate its effectiveness in a simulation environment. Experimental results show the DoSGuard achieves 98.72% detecion precision, and the average CPU utilization of the controller is only around 8%. The results demonstrate that DoSGuard can effectively mitigate DoS attacks against SDN with limited overhead. |
format | Online Article Text |
id | pubmed-8840592 |
institution | National Center for Biotechnology Information |
language | English |
publishDate | 2022 |
publisher | MDPI |
record_format | MEDLINE/PubMed |
spelling | pubmed-88405922022-02-13 DoSGuard: Mitigating Denial-of-Service Attacks in Software-Defined Networks Li, Jishuai Tu, Tengfei Li, Yongsheng Qin, Sujuan Shi, Yijie Wen, Qiaoyan Sensors (Basel) Article Software-defined networking (SDN) is a new networking paradigm that realizes the fast management and optimal configuration of network resources by decoupling control logic and forwarding functions. However, centralized network architecture brings new security problems, and denial-of-service (DoS) attacks are among the most critical threats. Due to the lack of an effective message-verification mechanism in SDN, attackers can easily launch a DoS attack by faking the source address information. This paper presents DoSGuard, an efficient and protocol-independent defense framework for SDN networks to detect and mitigate such attacks. DoSGuard is a lightweight extension module on SDN controllers that mainly consists of three key components: a monitor, a detector, and a mitigator. The monitor maintains the information between the switches and the hosts for anomaly detection. The detector utilizes OpenFlow message and flow features to detect the attack. The mitigator protects networks by filtering malicious packets. We implement a prototype of DoSGuard in the floodlight controller and evaluate its effectiveness in a simulation environment. Experimental results show the DoSGuard achieves 98.72% detecion precision, and the average CPU utilization of the controller is only around 8%. The results demonstrate that DoSGuard can effectively mitigate DoS attacks against SDN with limited overhead. MDPI 2022-01-29 /pmc/articles/PMC8840592/ /pubmed/35161800 http://dx.doi.org/10.3390/s22031061 Text en © 2022 by the authors. https://creativecommons.org/licenses/by/4.0/Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (https://creativecommons.org/licenses/by/4.0/). |
spellingShingle | Article Li, Jishuai Tu, Tengfei Li, Yongsheng Qin, Sujuan Shi, Yijie Wen, Qiaoyan DoSGuard: Mitigating Denial-of-Service Attacks in Software-Defined Networks |
title | DoSGuard: Mitigating Denial-of-Service Attacks in Software-Defined Networks |
title_full | DoSGuard: Mitigating Denial-of-Service Attacks in Software-Defined Networks |
title_fullStr | DoSGuard: Mitigating Denial-of-Service Attacks in Software-Defined Networks |
title_full_unstemmed | DoSGuard: Mitigating Denial-of-Service Attacks in Software-Defined Networks |
title_short | DoSGuard: Mitigating Denial-of-Service Attacks in Software-Defined Networks |
title_sort | dosguard: mitigating denial-of-service attacks in software-defined networks |
topic | Article |
url | https://www.ncbi.nlm.nih.gov/pmc/articles/PMC8840592/ https://www.ncbi.nlm.nih.gov/pubmed/35161800 http://dx.doi.org/10.3390/s22031061 |
work_keys_str_mv | AT lijishuai dosguardmitigatingdenialofserviceattacksinsoftwaredefinednetworks AT tutengfei dosguardmitigatingdenialofserviceattacksinsoftwaredefinednetworks AT liyongsheng dosguardmitigatingdenialofserviceattacksinsoftwaredefinednetworks AT qinsujuan dosguardmitigatingdenialofserviceattacksinsoftwaredefinednetworks AT shiyijie dosguardmitigatingdenialofserviceattacksinsoftwaredefinednetworks AT wenqiaoyan dosguardmitigatingdenialofserviceattacksinsoftwaredefinednetworks |