首页> 外文期刊>Journal of High Speed Networks >A two level security mechanism to detect a DDoS flooding attack in software-defined networks using entropy-based and C4.5 technique
【24h】

A two level security mechanism to detect a DDoS flooding attack in software-defined networks using entropy-based and C4.5 technique

机译:使用基于熵和C4.5技术检测软件定义网络中DDOS泛洪攻击的两个级别安全机制

获取原文
获取原文并翻译 | 示例
       

摘要

Software-Defined Network (SDN) has recently emerged as a network paradigm due to its high network programmability and flexibility which can overcome the problem in traditional networks by decoupling the control plane from the data plane. The data plane will forward the packets as per the decision made by the controller in the control plane. This centralized control will help to provide the abstract view of the entire network infrastructure. Since the controller is a core part of SDN, it is more prone for attacks and turns as a major threat to the entire network. Distributed Denial of Service (DDoS) attack can then overload the SDN controller and switch flow table which leads to a performance degrade of the network. To address this problem, we have deployed two level security mechanisms. In level one, an entropy-based mechanism is proposed to detect the DDoS flooding attack in the early stage by temporarily holding the particular flow. In level two, a machine learning-based C4.5 technique is proposed to detect the attack by analysing additional features and send a permanent alert to drop the packets. The results are analysed with K-fold validation technique in terms of sensitivity, specificity and accuracy.
机译:由于其高网络可编程性和灵活性,最近被授予了网络范例的软件定义的网络(SDN),这可以通过从数据平面解耦控制平面来克服传统网络中的问题。数据平面将根据控制器中的控制器所做的决定转发数据包。这种集中控制将有助于提供整个网络基础架构的抽象视图。由于控制器是SDN的核心部分,因此攻击更容易发生作为对整个网络的主要威胁。然后,分布式拒绝服务(DDOS)攻击可以过载SDN控制器和开关流动表,这导致网络的性能下降。要解决此问题,我们已部署了两个级别的安全机制。在第一级中,提出了一种基于熵的机制,通过临时持有特定流程来检测早期阶段的DDOS泛滥攻击。在二级中,提出了一种基于机器学习的C4.5技术来通过分析附加功能来检测攻击,并发送永久警报以删除数据包。在敏感度,特异性和准确性方面,用K折验证技术分析结果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号