A Model-Driven Framework for the Prevention of DoS Attacks in Software Defined Networking (SDN)

M. Farooq, M. Rashid, F. Azam, Yawar Rasheed, Muhammad Waseem Anwar, Zohaib Shahid
{"title":"A Model-Driven Framework for the Prevention of DoS Attacks in Software Defined Networking (SDN)","authors":"M. Farooq, M. Rashid, F. Azam, Yawar Rasheed, Muhammad Waseem Anwar, Zohaib Shahid","doi":"10.1109/SysCon48628.2021.9447131","DOIUrl":null,"url":null,"abstract":"Security is a key component of the network. Software Defined Networking (SDN) is a refined form of traditional network management system. It is a new encouraging approach to design-build and manage networks. SDN decouples control plane (software-based router) and data plane (software-based switch), hence it is programmable. Consequently, it facilitates implementation of security based applications for the prevention of DOS attacks. Various solutions have been proposed by researches for handling of DOS attacks in SDN. However, these solutions are very limited in scope, complex, time consuming and change resistant. In this article, we have proposed a novel model driven framework i.e. MDAP (Model Based DOS Attacks Prevention) Framework. Particularly, a meta model is proposed. As tool support, a tree editor and a Sirius based graphical modeling tool with drag drop palette have been developed in Oboe designer community edition. The tool support allows modeling and visualization of simple and complex network topology scenarios. A Model to Text transformation engine has also been made part of framework that generates java code for the Floodlight SDN controller from the modeled scenario. The validity of proposed framework has been demonstrated via case study. The results prove that the proposed framework can effectively handle DOS attacks in SDN with simplicity as per the true essence of MDSE and can be reliably used for the automation of security based applications in order to deny DOS attacks in SDN","PeriodicalId":384949,"journal":{"name":"2021 IEEE International Systems Conference (SysCon)","volume":"42 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2021-04-15","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2021 IEEE International Systems Conference (SysCon)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/SysCon48628.2021.9447131","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2

Abstract

Security is a key component of the network. Software Defined Networking (SDN) is a refined form of traditional network management system. It is a new encouraging approach to design-build and manage networks. SDN decouples control plane (software-based router) and data plane (software-based switch), hence it is programmable. Consequently, it facilitates implementation of security based applications for the prevention of DOS attacks. Various solutions have been proposed by researches for handling of DOS attacks in SDN. However, these solutions are very limited in scope, complex, time consuming and change resistant. In this article, we have proposed a novel model driven framework i.e. MDAP (Model Based DOS Attacks Prevention) Framework. Particularly, a meta model is proposed. As tool support, a tree editor and a Sirius based graphical modeling tool with drag drop palette have been developed in Oboe designer community edition. The tool support allows modeling and visualization of simple and complex network topology scenarios. A Model to Text transformation engine has also been made part of framework that generates java code for the Floodlight SDN controller from the modeled scenario. The validity of proposed framework has been demonstrated via case study. The results prove that the proposed framework can effectively handle DOS attacks in SDN with simplicity as per the true essence of MDSE and can be reliably used for the automation of security based applications in order to deny DOS attacks in SDN
软件定义网络(SDN)中防止DoS攻击的模型驱动框架
安全是网络的关键组成部分。软件定义网络(SDN)是传统网络管理系统的一种改进形式。这是一种设计、建设和管理网络的新方法。SDN将控制平面(基于软件的路由器)和数据平面(基于软件的交换机)解耦,因此是可编程的。因此,它促进了基于安全的应用程序的实现,以防止DOS攻击。针对SDN中DOS攻击的处理,研究人员提出了多种解决方案。然而,这些解决方案的范围非常有限、复杂、耗时且不易更改。在本文中,我们提出了一个新的模型驱动框架,即MDAP(基于模型的DOS攻击预防)框架。特别提出了一个元模型。作为工具支持,在Oboe设计器社区版中开发了一个树编辑器和一个基于Sirius的带有拖放调色板的图形化建模工具。该工具支持对简单和复杂的网络拓扑场景进行建模和可视化。一个从模型到文本的转换引擎也已经成为框架的一部分,它从建模的场景中为泛光灯SDN控制器生成java代码。通过实例分析,验证了该框架的有效性。实验结果表明,该框架能够有效地、简单地处理SDN中的DOS攻击,体现了MDSE的本质,能够可靠地用于基于安全的应用的自动化,以抵御SDN中的DOS攻击
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信