{"title":"SECO: SDN sEcure COntroller algorithm for detecting and defending denial of service attacks","authors":"Song Wang, K. G. Chavez, S. Kandeepan","doi":"10.1109/ICOICT.2017.8074692","DOIUrl":null,"url":null,"abstract":"Software Defined Network (SDN) brings additional flexibility to the traditional network allowing the implementation of intelligent information processing. SDN introduces a new architecture, where the controller acts as the brain of the network controlling several tasks such as routing, load balancing and providing the required quality of service (QoS). However, having a centralized controller makes the network vulnerable in terms of security. This paper introduces SDN sEcure COntroller (SECO) a novel and simple detect and defense algorithm, running in the controller, for improving SDN security features under Denial of Service (DoS) attacks. The network performance during attack is tested with and without the SECO algorithm. In this paper we show by means of simulations that the DoS attacks can degrade the controller's performance and the proposed algorithm could significantly reduce the impact of such DoS attacks.","PeriodicalId":244500,"journal":{"name":"2017 5th International Conference on Information and Communication Technology (ICoIC7)","volume":"46 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2017-05-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"19","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2017 5th International Conference on Information and Communication Technology (ICoIC7)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICOICT.2017.8074692","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 19
Abstract
Software Defined Network (SDN) brings additional flexibility to the traditional network allowing the implementation of intelligent information processing. SDN introduces a new architecture, where the controller acts as the brain of the network controlling several tasks such as routing, load balancing and providing the required quality of service (QoS). However, having a centralized controller makes the network vulnerable in terms of security. This paper introduces SDN sEcure COntroller (SECO) a novel and simple detect and defense algorithm, running in the controller, for improving SDN security features under Denial of Service (DoS) attacks. The network performance during attack is tested with and without the SECO algorithm. In this paper we show by means of simulations that the DoS attacks can degrade the controller's performance and the proposed algorithm could significantly reduce the impact of such DoS attacks.
软件定义网络(SDN)为传统网络带来了更多的灵活性,使智能信息处理成为可能。SDN 引入了一种新的架构,在这种架构中,控制器充当网络的大脑,控制路由选择、负载平衡和提供所需的服务质量(QoS)等多项任务。然而,集中式控制器会使网络在安全性方面变得脆弱。本文介绍了 SDN sEcure COntroller (SECO),这是一种在控制器中运行的新颖、简单的检测和防御算法,用于改善拒绝服务(DoS)攻击下的 SDN 安全特性。在使用和不使用 SECO 算法的情况下,对攻击期间的网络性能进行了测试。本文通过仿真表明,DoS 攻击会降低控制器的性能,而建议的算法可以显著降低此类 DoS 攻击的影响。