4.5 Article

Software defined network-based HTTP flooding attack defender

Journal

COMPUTERS & ELECTRICAL ENGINEERING
Volume 101, Issue -, Pages -

Publisher

PERGAMON-ELSEVIER SCIENCE LTD
DOI: 10.1016/j.compeleceng.2022.108019

Keywords

HTTP flooding attack; SDN; Entropy; Hellinger distance

Ask authors/readers for more resources

This paper proposes a method to mitigate HTTP flooding attacks using Software-Defined Networking (SDN), by implementing a defense module on the SDN controller to detect and mitigate the attack. Experimental results show that this approach achieves significant improvements in detection time and the number of blocked malicious flows compared to state-of-the-art methods.
In recent years, the explosive growth of the Internet has led to an increment in the number of Distributed Denial of Service (DDoS) attacks. HTTP Flooding is a critical DDoS attack that targets HTTP servers to prohibit users from receiving HTTP services. Moreover, it saturates the link bandwidth and consumes network resources. Because the attack is launched at the application layer, it is difficult to defend against it using current countermeasures such as firewall or Intrusion Prevention System (IPS).In this paper, we propose SHFD, which leverages the Software-Defined Networking (SDN) paradigm to mitigate HTTP flooding attacks. We implement SHFD as a defender module on the SDN controller to detect and mitigate the attack in the first place. Experimental results gathered from Mininet confirm that SHFD brings a significant improvement of 13% in detection time and 29% in the number of blocked malicious flows compared to the state-of-the-art approaches.

Authors

I am an author on this paper
Click your name to claim this paper and add it to your profile.

Reviews

Primary Rating

4.5
Not enough ratings

Secondary Ratings

Novelty
-
Significance
-
Scientific rigor
-
Rate this paper

Recommended

No Data Available
No Data Available