Loading [MathJax]/extensions/MathZoom.js
A New Framework for DDoS Attack Detection and Defense in SDN Environment | IEEE Journals & Magazine | IEEE Xplore

A New Framework for DDoS Attack Detection and Defense in SDN Environment


The DDoS detection and defense framework we proposed includes the trigger mechanism on data plane, the combined machine learning algorithm based on K-Means and KNN on the...

Abstract:

While software defined network (SDN) brings more innovation to the development of future networks, it also faces a more severe threat from DDoS attacks. In order to deal ...Show More

Abstract:

While software defined network (SDN) brings more innovation to the development of future networks, it also faces a more severe threat from DDoS attacks. In order to deal with the single point of failure on SDN controller caused by DDoS attacks, we propose a framework for detection and defense of DDoS attacks in the SDN environment. Firstly, we deploy a trigger mechanism of DDoS attack detection on data plane to screen for abnormal flows in the network. Then, we use a combined machine learning algorithm based on K-Means and KNN to exploit the rate characteristics and asymmetry characteristics of the flows and to detect the suspicious flows determined by the detection trigger mechanism. Finally, the controller will take corresponding actions to defense against the attacks. In this paper, we propose a new framework of cooperative detection methods of control plane and data plane, which effectively improve the detection accuracy and efficiency, and prevent DDoS attacks on SDN.
The DDoS detection and defense framework we proposed includes the trigger mechanism on data plane, the combined machine learning algorithm based on K-Means and KNN on the...
Published in: IEEE Access ( Volume: 8)
Page(s): 161908 - 161919
Date of Publication: 03 September 2020
Electronic ISSN: 2169-3536

Funding Agency:


References

References is not available for this document.