Detection of Control Layer DDoS Attack using Entropy metrics in SDN: An Empirical Investigation

Kshira Sagar Sahoo, B. Sahoo, Manikanta Vankayala, Ratnakar Dash
{"title":"Detection of Control Layer DDoS Attack using Entropy metrics in SDN: An Empirical Investigation","authors":"Kshira Sagar Sahoo, B. Sahoo, Manikanta Vankayala, Ratnakar Dash","doi":"10.1109/ICOAC.2017.8441392","DOIUrl":null,"url":null,"abstract":"The Software Defined Networks (SDN) and OpenFlow technologies become the emerging networking technology that supports the dynamic nature of the network functions through simplified network management. The main innovation behind SDN is the decoupling of forwarding plane and control plane. In control plane, the controller provides a pivotal point of control to distribute the policy information throughout the network through a standard protocol like OpenFlow. Despite numerous benefits, SDN security is still a matter of concern among the research communities. The Distributed Denial-of-Service (DDoS) attack have been posing a tremendous threat to the Internet since a long back. The variant of this attack is quickly becoming more and more complex. With the advancement in network technologies, on the one hand SDN become an important tool to defeat DDoS attacks, but on another hand, it becomes a victim of DDoS attacks due to the potential vulnerabilities exist across various SDN layer. Moreover, this article focuses on the DDoS threat to control plane which is the central point of SDN. The entropy-based DDoS detection method is a wildly used technique in the traditional network. For detection of DDoS attack in control layer of SDN, few works have employed entropy method. In this paper, taking the advantages of flow based nature of SDN, we proposed General Entropy (GE) based DDoS attack detection mechanism. The experimental results show that our detection mechanism can detect the attack quickly and achieve a high detection accuracy with a low false positive rate.","PeriodicalId":329949,"journal":{"name":"2017 Ninth International Conference on Advanced Computing (ICoAC)","volume":"80 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2017-12-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2017 Ninth International Conference on Advanced Computing (ICoAC)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICOAC.2017.8441392","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 3

Abstract

The Software Defined Networks (SDN) and OpenFlow technologies become the emerging networking technology that supports the dynamic nature of the network functions through simplified network management. The main innovation behind SDN is the decoupling of forwarding plane and control plane. In control plane, the controller provides a pivotal point of control to distribute the policy information throughout the network through a standard protocol like OpenFlow. Despite numerous benefits, SDN security is still a matter of concern among the research communities. The Distributed Denial-of-Service (DDoS) attack have been posing a tremendous threat to the Internet since a long back. The variant of this attack is quickly becoming more and more complex. With the advancement in network technologies, on the one hand SDN become an important tool to defeat DDoS attacks, but on another hand, it becomes a victim of DDoS attacks due to the potential vulnerabilities exist across various SDN layer. Moreover, this article focuses on the DDoS threat to control plane which is the central point of SDN. The entropy-based DDoS detection method is a wildly used technique in the traditional network. For detection of DDoS attack in control layer of SDN, few works have employed entropy method. In this paper, taking the advantages of flow based nature of SDN, we proposed General Entropy (GE) based DDoS attack detection mechanism. The experimental results show that our detection mechanism can detect the attack quickly and achieve a high detection accuracy with a low false positive rate.
基于熵度量的SDN控制层DDoS攻击检测:实证研究
SDN (Software Defined Networks)和OpenFlow技术通过简化网络管理,支持网络功能的动态性,成为新兴的网络技术。SDN的主要创新是转发平面和控制平面的解耦。在控制平面上,控制器提供了一个控制点,通过OpenFlow等标准协议在整个网络中分发策略信息。尽管有很多好处,SDN的安全性仍然是研究界关注的问题。长期以来,分布式拒绝服务(DDoS)攻击对互联网构成了巨大的威胁。这种攻击的变体正迅速变得越来越复杂。随着网络技术的进步,SDN一方面成为抵御DDoS攻击的重要工具,但另一方面,由于SDN各层存在潜在的漏洞,也成为DDoS攻击的受害者。此外,本文还重点研究了作为SDN中心点的DDoS威胁控制平面。基于熵的DDoS检测方法是传统网络中广泛使用的一种检测方法。对于SDN控制层的DDoS攻击检测,采用熵法的工作很少。本文利用SDN基于流的特性,提出了基于通用熵(GE)的DDoS攻击检测机制。实验结果表明,我们的检测机制能够快速检测出攻击,检测精度高,假阳性率低。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信