基于角色的SDN DDoS攻击检测统计机制

Phan The Duy, Do Thi Thu Hien, V. Pham
{"title":"基于角色的SDN DDoS攻击检测统计机制","authors":"Phan The Duy, Do Thi Thu Hien, V. Pham","doi":"10.1109/NICS.2018.8606851","DOIUrl":null,"url":null,"abstract":"There is a transformation of the traditional network into Software Defined Networking (SDN) which is an outstanding developing area recently. Among the most exciting features of SDN are the remarkable control over network infrastructure and decoupling of control and data plane. Although it helps more flexible network management, SDN should be considered current and upcoming security threats associated with its deployment. One of them is the DDoS attack which is a malicious attempt to bring down networks, applications, or services by overwhelming these resources with too much data or impairing them in some other ways. In SDN, we can offer or change the network functions or behavior program by monitoring controller to realize DDoS attacks. This paper presents an approach of DDoS attack detection in SDN environment by utilizing the entropy metric with consideration of differences in host role profile to suspect under-attack state, we also deal with time factor in information collecting activities. Then, a statistical method is used for investigating flow information sent from OpenFlow switches to confirm the previous suspicion.","PeriodicalId":137666,"journal":{"name":"2018 5th NAFOSTED Conference on Information and Computer Science (NICS)","volume":"2 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2018-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"11","resultStr":"{\"title\":\"A role-based statistical mechanism for DDoS attack detection in SDN\",\"authors\":\"Phan The Duy, Do Thi Thu Hien, V. Pham\",\"doi\":\"10.1109/NICS.2018.8606851\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"There is a transformation of the traditional network into Software Defined Networking (SDN) which is an outstanding developing area recently. Among the most exciting features of SDN are the remarkable control over network infrastructure and decoupling of control and data plane. Although it helps more flexible network management, SDN should be considered current and upcoming security threats associated with its deployment. One of them is the DDoS attack which is a malicious attempt to bring down networks, applications, or services by overwhelming these resources with too much data or impairing them in some other ways. In SDN, we can offer or change the network functions or behavior program by monitoring controller to realize DDoS attacks. This paper presents an approach of DDoS attack detection in SDN environment by utilizing the entropy metric with consideration of differences in host role profile to suspect under-attack state, we also deal with time factor in information collecting activities. Then, a statistical method is used for investigating flow information sent from OpenFlow switches to confirm the previous suspicion.\",\"PeriodicalId\":137666,\"journal\":{\"name\":\"2018 5th NAFOSTED Conference on Information and Computer Science (NICS)\",\"volume\":\"2 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2018-11-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"11\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2018 5th NAFOSTED Conference on Information and Computer Science (NICS)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/NICS.2018.8606851\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2018 5th NAFOSTED Conference on Information and Computer Science (NICS)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/NICS.2018.8606851","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 11

摘要

传统网络向软件定义网络(SDN)的转变是近年来一个突出的发展方向。SDN最令人兴奋的特性之一是对网络基础设施的卓越控制以及控制和数据平面的解耦。尽管它有助于更灵活的网络管理,但SDN应该考虑与其部署相关的当前和未来的安全威胁。其中之一是DDoS攻击,这是一种恶意的尝试,通过使用过多的数据压倒这些资源或以其他方式损害它们来破坏网络,应用程序或服务。在SDN中,我们可以通过监控控制器提供或改变网络功能或行为程序来实现DDoS攻击。本文提出了一种SDN环境下的DDoS攻击检测方法,该方法利用熵度量来考虑主机角色特征的差异来怀疑受攻击状态,并处理了信息收集活动中的时间因素。然后,使用统计方法对OpenFlow交换机发送的流量信息进行调查,以证实之前的怀疑。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
A role-based statistical mechanism for DDoS attack detection in SDN
There is a transformation of the traditional network into Software Defined Networking (SDN) which is an outstanding developing area recently. Among the most exciting features of SDN are the remarkable control over network infrastructure and decoupling of control and data plane. Although it helps more flexible network management, SDN should be considered current and upcoming security threats associated with its deployment. One of them is the DDoS attack which is a malicious attempt to bring down networks, applications, or services by overwhelming these resources with too much data or impairing them in some other ways. In SDN, we can offer or change the network functions or behavior program by monitoring controller to realize DDoS attacks. This paper presents an approach of DDoS attack detection in SDN environment by utilizing the entropy metric with consideration of differences in host role profile to suspect under-attack state, we also deal with time factor in information collecting activities. Then, a statistical method is used for investigating flow information sent from OpenFlow switches to confirm the previous suspicion.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信