K. Hosny, Ameer E. Gouda, Ehab R. Mohamed
{"title":"软件定义网络分布式拒绝服务攻击的新检测机制","authors":"K. Hosny, Ameer E. Gouda, Ehab R. Mohamed","doi":"10.4018/ijskd.2020040101","DOIUrl":null,"url":null,"abstract":"Softwaredefinednetworks(SDN)arearecentlydevelopedformforcontrollingnetworkmanagement byprovidingcentralizedcontrolunitcalledtheController.ThismasterControllerisagreatpower pointbutatthesametimeitisunfortunatelyafailurepointandaseriousloopholeifitistargetedand droppedbyattacks.OneofthemostserioustypesofattacksistheinabilitytoaccesstheController, whichisknownasthedistributeddenialofservice(DDoS)attack.ThisresearchshowshowDDoS attackcandeplete the resourcesof theControllerandproposesa lightweightmechanism,which worksattheControlleranddetectsaDDoSattackintheearlystages.Theproposedmechanismcan notonlydetecttheattack,butalsoidentifyattackpathsandinitiateamitigationprocesstoprovide somedegreeofprotectiontonetworkdevicesimmediatelyaftertheattackisdetected.Theproposed mechanismdependsonahybridtechniquethatmergesbetweentheaverageflowinitiationrate,and theflowspecificationofthecomingtraffictothenetwork. KeywoRDS Average Flow Initiation Rate, DDoS Attacks, Flow Initiation Rate, Flow Specification, SDN Controller, SDN, Security, Window Size","PeriodicalId":13656,"journal":{"name":"Int. J. Sociotechnology Knowl. Dev.","volume":"3 1","pages":"1-30"},"PeriodicalIF":0.0000,"publicationDate":"2020-04-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"6","resultStr":"{\"title\":\"New Detection Mechanism for Distributed Denial of Service Attacks in Software Defined Networks\",\"authors\":\"K. Hosny, Ameer E. Gouda, Ehab R. Mohamed\",\"doi\":\"10.4018/ijskd.2020040101\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Softwaredefinednetworks(SDN)arearecentlydevelopedformforcontrollingnetworkmanagement byprovidingcentralizedcontrolunitcalledtheController.ThismasterControllerisagreatpower pointbutatthesametimeitisunfortunatelyafailurepointandaseriousloopholeifitistargetedand droppedbyattacks.OneofthemostserioustypesofattacksistheinabilitytoaccesstheController, whichisknownasthedistributeddenialofservice(DDoS)attack.ThisresearchshowshowDDoS attackcandeplete the resourcesof theControllerandproposesa lightweightmechanism,which worksattheControlleranddetectsaDDoSattackintheearlystages.Theproposedmechanismcan notonlydetecttheattack,butalsoidentifyattackpathsandinitiateamitigationprocesstoprovide somedegreeofprotectiontonetworkdevicesimmediatelyaftertheattackisdetected.Theproposed mechanismdependsonahybridtechniquethatmergesbetweentheaverageflowinitiationrate,and theflowspecificationofthecomingtraffictothenetwork. KeywoRDS Average Flow Initiation Rate, DDoS Attacks, Flow Initiation Rate, Flow Specification, SDN Controller, SDN, Security, Window Size\",\"PeriodicalId\":13656,\"journal\":{\"name\":\"Int. J. Sociotechnology Knowl. Dev.\",\"volume\":\"3 1\",\"pages\":\"1-30\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2020-04-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"6\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Int. J. Sociotechnology Knowl. Dev.\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.4018/ijskd.2020040101\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Int. J. Sociotechnology Knowl. Dev.","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.4018/ijskd.2020040101","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 6
New Detection Mechanism for Distributed Denial of Service Attacks in Software Defined Networks
Softwaredefinednetworks(SDN)arearecentlydevelopedformforcontrollingnetworkmanagement byprovidingcentralizedcontrolunitcalledtheController.ThismasterControllerisagreatpower pointbutatthesametimeitisunfortunatelyafailurepointandaseriousloopholeifitistargetedand droppedbyattacks.OneofthemostserioustypesofattacksistheinabilitytoaccesstheController, whichisknownasthedistributeddenialofservice(DDoS)attack.ThisresearchshowshowDDoS attackcandeplete the resourcesof theControllerandproposesa lightweightmechanism,which worksattheControlleranddetectsaDDoSattackintheearlystages.Theproposedmechanismcan notonlydetecttheattack,butalsoidentifyattackpathsandinitiateamitigationprocesstoprovide somedegreeofprotectiontonetworkdevicesimmediatelyaftertheattackisdetected.Theproposed mechanismdependsonahybridtechniquethatmergesbetweentheaverageflowinitiationrate,and theflowspecificationofthecomingtraffictothenetwork. KeywoRDS Average Flow Initiation Rate, DDoS Attacks, Flow Initiation Rate, Flow Specification, SDN Controller, SDN, Security, Window Size