4.5 Article

Collaborative detection and mitigation of DDoS in software-defined networks

期刊

JOURNAL OF SUPERCOMPUTING
卷 77, 期 11, 页码 13166-13190

出版社

SPRINGER
DOI: 10.1007/s11227-021-03782-9

关键词

Software-defined network; Distributed denial-of-service; Redis simple message queue; Machine learning; Ensemble classifier

向作者/读者索取更多资源

This research introduces a method for detecting and mitigating DDoS attacks in software defined networks, utilizing an ensemble classifier named V-NKDE which shows high accuracy across different datasets. The proposed method demonstrates effective attack detection and mitigation, with significantly reduced false positive rates and low controller overhead in multi-controller domains.
This research presents the detection and mitigation of distributed denial of service (DDoS) in software defined networks (SDN). The proposed method consists of three modules: classifier module, mitigation module, and collaborative module. An ensemble classifier called V-NKDE is capable of detecting DDoS attacks accurately. The mitigation module blocks malicious traffics and purges entries of malicious traffic from the switch flow table. The collaborative module shares DDoS detection and mitigation rules among multiple SDN controllers using Redis Simple Message Queue mechanism. The proposed classifier performance validation on InSDN2020, CICIDS2017, NSL-KDD and UNSW-NB15 datasets. Furthermore we evaluated our proposed classifier in real traffic on an SDN simulation tested. The results show that the proposed method can detect DDoS attacks with high accuracy using an ensemble classifier, which performs better than single classifiers. More importantly, the false positive rate is greatly reduced, showing detection and mitigation of DDoS attacks across multi-controller domains with low controller overhead.

作者

我是这篇论文的作者
点击您的名字以认领此论文并将其添加到您的个人资料中。

评论

主要评分

4.5
评分不足

次要评分

新颖性
-
重要性
-
科学严谨性
-
评价这篇论文

推荐

暂无数据
暂无数据