Abstract:
DDoS attacks have emerged as one of the most serious network security threats in 5G, IoT, multi-cloud, and other emerging technology scenarios. The bandwidth of DDoS atta...Show MoreMetadata
Abstract:
DDoS attacks have emerged as one of the most serious network security threats in 5G, IoT, multi-cloud, and other emerging technology scenarios. The bandwidth of DDoS attacks is increasing in the new scenario, but the current network structure and security devices are inflexible. We propose a DDoS protection method based on SDN multi-dimensional scheduling method and DDoS scrubbing policy, which not only plans the scheduling path, but also blocks and redirects different kinds of attack traffic that used dynamic residual bandwidth of links, the number of flow entries in OpenFlow switches, and scheduling path length. To flexibly protect against DDoS attacks, this method combines scheduling and protection means. The experimental results indicate that the scheduling is effective. The scheduling, path produced by this method outperforms ECMP and KSP approaches in throughput, packet loss rate, and jitter, and it can block L3/L4 attack traffic and redirect L7 attack traffic.
Date of Conference: 13-15 December 2021
Date Added to IEEE Xplore: 13 April 2022
ISBN Information: