首页> 外文会议>IEEE International Conference on Advanced Computing >Detection of Control Layer DDoS Attack using Entropy metrics in SDN: An Empirical Investigation
【24h】

Detection of Control Layer DDoS Attack using Entropy metrics in SDN: An Empirical Investigation

机译:SDN中使用熵指标检测控制层DDoS攻击的实证研究

获取原文

摘要

The Software Defined Networks (SDN) and OpenFlow technologies become the emerging networking technology that supports the dynamic nature of the network functions through simplified network management. The main innovation behind SDN is the decoupling of forwarding plane and control plane. In control plane, the controller provides a pivotal point of control to distribute the policy information throughout the network through a standard protocol like OpenFlow. Despite numerous benefits, SDN security is still a matter of concern among the research communities. The Distributed Denial-of-Service (DDoS) attack have been posing a tremendous threat to the Internet since a long back. The variant of this attack is quickly becoming more and more complex. With the advancement in network technologies, on the one hand SDN become an important tool to defeat DDoS attacks, but on another hand, it becomes a victim of DDoS attacks due to the potential vulnerabilities exist across various SDN layer. Moreover, this article focuses on the DDoS threat to control plane which is the central point of SDN. The entropy-based DDoS detection method is a wildly used technique in the traditional network. For detection of DDoS attack in control layer of SDN, few works have employed entropy method. In this paper, taking the advantages of flow based nature of SDN, we proposed General Entropy (GE) based DDoS attack detection mechanism. The experimental results show that our detection mechanism can detect the attack quickly and achieve a high detection accuracy with a low false positive rate.
机译:软件定义网络(SDN)和OpenFlow技术成为新兴的联网技术,可通过简化的网络管理来支持网络功能的动态特性。 SDN背后的主要创新是转发平面和控制平面的分离。在控制平面中,控制器提供控制的关键点,以通过标准协议(如OpenFlow)在整个网络中分发策略信息。尽管有许多好处,但SDN安全仍然是研究界关注的问题。分布式拒绝服务(DDoS)攻击早就对Internet构成了巨大威胁。这种攻击的变种正在迅速变得越来越复杂。随着网络技术的发展,一方面,SDN成为抵御DDoS攻击的重要工具,但另一方面,由于各个SDN层中都存在潜在的漏洞,SDN成为DDoS攻击的受害者。此外,本文重点介绍DDoS对控制平面的威胁,这是SDN的中心点。基于熵的DDoS检测方法是传统网络中一种普遍使用的技术。为了检测SDN控制层中的DDoS攻击,很少采用熵方法。本文利用SDN基于流的本质优势,提出了基于通用熵(GE)的DDoS攻击检测机制。实验结果表明,我们的检测机制能够快速检测出攻击,并以较低的误报率实现了较高的检测精度。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号