Q-MIND: Defeating Stealthy DoS Attacks in SDN with a Machine-learning based Defense Framework

07/27/2019
by   Trung V. Phan, et al.
0

Software Defined Networking (SDN) enables flexible and scalable network control and management. However, it also introduces new vulnerabilities that can be exploited by attackers. In particular, low-rate and slow or stealthy Denial-of-Service (DoS) attacks are recently attracting attention from researchers because of their detection challenges. In this paper, we propose a novel machine learning based defense framework named Q-MIND, to effectively detect and mitigate stealthy DoS attacks in SDN-based networks. We first analyze the adversary model of stealthy DoS attacks, the related vulnerabilities in SDN-based networks and the key characteristics of stealthy DoS attacks. Next, we describe and analyze an anomaly detection system that uses a Reinforcement Learning-based approach based on Q-Learning in order to maximize its detection performance. Finally, we outline the complete Q-MIND defense framework that incorporates the optimal policy derived from the Q-Learning agent to efficiently defeat stealthy DoS attacks in SDN-based networks. An extensive comparison of the Q-MIND framework and currently existing methods shows that significant improvements in attack detection and mitigation performance are obtained by Q-MIND.

READ FULL TEXT
research
06/24/2019

In-Vehicle False Information Attack Detection and Mitigation Framework using Machine Learning and Software Defined Networking

A modern vehicle contains many electronic control units (ECUs), which co...
research
09/04/2019

Q-DATA: Enhanced Traffic Flow Monitoring in Software-Defined Networks applying Q-learning

Software-Defined Networking (SDN) introduces a centralized network contr...
research
04/08/2018

The Challenges in SDN/ML Based Network Security : A Survey

Machine Learning is gaining popularity in the network security domain as...
research
04/18/2018

SDN-Assisted Network-Based Mitigation of Slow DDoS Attacks

Slow-running attacks against network applications are often not easy to ...
research
01/14/2020

S3: A DFW-based Scalable Security State Analysis Framework for Large-Scale Data Center Networks

With an average network size approaching 8000 servers, datacenter networ...
research
09/22/2020

ORACLE: Collaboration of Data and Control Planes to Detect DDoS Attacks

The possibility of programming the control and data planes, enabled by t...
research
03/01/2021

Centralized and Distributed Intrusion Detection for Resource Constrained Wireless SDN Networks

Software-defined networking (SDN) was devised to simplify network manage...

Please sign up or login with your details

Forgot password? Click here to reset