Packet in message based DDoS attack detection in SDN network using OpenFlow

X You, Y Feng, K Sakurai - 2017 Fifth International Symposium …, 2017 - ieeexplore.ieee.org
X You, Y Feng, K Sakurai
2017 Fifth International Symposium on Computing and Networking …, 2017ieeexplore.ieee.org
Using the OpenFlow protocol, the virtual network technology SDN (Software Defined
Network) is now widely used. In recent years, the number of DDoS attacks has been
increasing year by year. To detect DDoS attacks in SDN, data recorded in the flow table in
OpenFlow switch is analyzed and various detection methods are submitted. However, SDN
centrally manages communication within the network, when detecting DDoS (Distributed
Denial of Service) attacks. This creates a heavy processing load, and the processing load of …
Using the OpenFlow protocol, the virtual network technology SDN (Software Defined Network) is now widely used. In recent years, the number of DDoS attacks has been increasing year by year. To detect DDoS attacks in SDN, data recorded in the flow table in OpenFlow switch is analyzed and various detection methods are submitted. However, SDN centrally manages communication within the network, when detecting DDoS (Distributed Denial of Service) attacks. This creates a heavy processing load, and the processing load of the OpenFlow controller must be considered. In this paper, in order to reduce the processing load of the controller, we do not collect data of the flow table, extract three features from the Packet In message for communication between the controller and the switch, and perform real-time attack detection. Furthermore, to avoid stringent detection time intervals, triggers will be added before detection to realize light and dynamic DDoS attacks detection.
ieeexplore.ieee.org
Showing the best result for this search. See all results