3.8 Proceedings Paper

Design and Implementation of an OpenFlow-based TCP SYN Flood Mitigation

出版社

IEEE
DOI: 10.1109/MobileCloud.2018.00014

关键词

OpenFlow; DDoS Attack; TCP SYN Flood

资金

  1. JSPS KAKENHI [JP15K00138]

向作者/读者索取更多资源

A Distributed Denial of Service attack is one of the top security threat in the Internet. Many security dedicated devices have been developed to mitigate those DDoS attacks. Those devices always need to be improved to handle various and up-to-date schemes of DDoS attacks and exhaust of those traffics. In the mobile cloud environment, each mobile node may become a source of these attacks when it is infected with virus or worms, then the attacks are arisen in the mobile network or the edge between mobile and cloud networks. These attacks are hard to defend at a single heavy protection point, such as a firewall, like current Internet environment. A thin and wide spread protection architecture is expected. In this paper, we propose a mitigation mechanism built into the network infrastructure using OpenFlow. OpenFlow achieves centralized and flexible network management by decoupling the data plane and control plane. The behavior of packets is decided by the controller software which distinguishes them using header information from Layer 1 to Layer 4. The proposed mechanism uses TCP SYN Authentication method to mitigate TCP SYN Flood Attacks. We describe the design and implementation of the mechanism, then show the result of preliminary evaluation.

作者

我是这篇论文的作者
点击您的名字以认领此论文并将其添加到您的个人资料中。

评论

主要评分

3.8
评分不足

次要评分

新颖性
-
重要性
-
科学严谨性
-
评价这篇论文

推荐

暂无数据
暂无数据