A Dynamic Hybrid Timeout Method to Secure Flow Tables Against DDoS Attacks in SDN

Balram Sooden, Mohammad Reza Abbasi
{"title":"A Dynamic Hybrid Timeout Method to Secure Flow Tables Against DDoS Attacks in SDN","authors":"Balram Sooden, Mohammad Reza Abbasi","doi":"10.1109/ICSCCC.2018.8703307","DOIUrl":null,"url":null,"abstract":"Distributed Denial of Service attacks are one of the major threats to network-based services today. Software Defined Networks (SDN) has the potential to evolve into a much more secure network paradigm than a traditional network as the whole network is controlled by a central controller having a complete view of the network. Being a considerably new concept, there are certain research problems related to SDN which are still needed to be addressed. Our work focuses on the collection of flow statistics to record the complete current and historical dynamics of the network by the controller to enable it to detect and prevent anomalous behavior in the network. Another research problem addressed in this paper is based on the Ternary Content Addressable Memory (TCAM) limitation of SDN based switches, which can be exploited with malicious hosts generating discrete network flows. To address this problem we propose the Dynamic Hybrid Timeout Method. It uses a blend of idle and hard timeout methods in addition to the Peer Support Strategy to enhance the durability of TCAM memory during flow table overloading DDoS attacks. The simulation results show that the Dynamic Hybrid Timeout Method enhances the performance of the Peer Support Strategy and adds durability in flow table memory utilization.","PeriodicalId":148491,"journal":{"name":"2018 First International Conference on Secure Cyber Computing and Communication (ICSCCC)","volume":"2 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2018-12-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"4","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2018 First International Conference on Secure Cyber Computing and Communication (ICSCCC)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICSCCC.2018.8703307","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 4

Abstract

Distributed Denial of Service attacks are one of the major threats to network-based services today. Software Defined Networks (SDN) has the potential to evolve into a much more secure network paradigm than a traditional network as the whole network is controlled by a central controller having a complete view of the network. Being a considerably new concept, there are certain research problems related to SDN which are still needed to be addressed. Our work focuses on the collection of flow statistics to record the complete current and historical dynamics of the network by the controller to enable it to detect and prevent anomalous behavior in the network. Another research problem addressed in this paper is based on the Ternary Content Addressable Memory (TCAM) limitation of SDN based switches, which can be exploited with malicious hosts generating discrete network flows. To address this problem we propose the Dynamic Hybrid Timeout Method. It uses a blend of idle and hard timeout methods in addition to the Peer Support Strategy to enhance the durability of TCAM memory during flow table overloading DDoS attacks. The simulation results show that the Dynamic Hybrid Timeout Method enhances the performance of the Peer Support Strategy and adds durability in flow table memory utilization.
基于动态混合超时的SDN流表抗DDoS攻击保护方法
分布式拒绝服务攻击是当今基于网络的服务的主要威胁之一。软件定义网络(SDN)有可能发展成为比传统网络更安全的网络范例,因为整个网络由具有完整网络视图的中央控制器控制。SDN作为一个相当新的概念,存在着一些需要解决的研究问题。我们的工作重点是收集流量统计数据,通过控制器记录网络的完整当前和历史动态,使其能够检测和防止网络中的异常行为。本文研究的另一个问题是基于SDN交换机的三元内容可寻址内存(TCAM)限制,这可能被恶意主机利用,产生离散的网络流。为了解决这个问题,我们提出了动态混合超时方法。除了对等支持策略外,它还混合使用空闲超时和硬超时方法来增强流表过载DDoS攻击期间TCAM内存的持久性。仿真结果表明,动态混合超时方法提高了对等支持策略的性能,增加了流表内存利用率的持久性。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信