SDN-Based Intrusion Detection System for Early Detection and Mitigation of DDoS Attacks

04/15/2021
by   Pedro Manso, et al.
0

The current paper addresses relevant network security vulnerabilities introduced by network devices within the emerging paradigm of Internet of Things (IoT) as well as the urgent need to mitigate the negative effects of some types of Distributed Denial of Service (DDoS) attacks that try to explore those security weaknesses. We design and implement a Software-Defined Intrusion Detection System (IDS) that reactively impairs the attacks at its origin, ensuring the normal operation of the network infrastructure. Our proposal includes an IDS that automatically detects several DDoS attacks, and then as an attack is detected, it notifies a Software Defined Networking (SDN) controller. The current proposal also downloads some convenient traffic forwarding decisions from the SDN controller to network devices. The evaluation results suggest that our proposal timely detects several types of cyber-attacks based on DDoS, mitigates their negative impacts on the network performance, and ensures the correct data delivery of normal traffic. Our work sheds light on the programming relevance over an abstracted view of the network infrastructure to timely detect a Botnet exploitation, mitigate malicious traffic at its source, and protect benign traffic.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
05/30/2019

SDN-based In-network Honeypot: Preemptively Disrupt and Mislead Attacks in IoT Networks

Detecting cyber attacks in the network environments used by Internet-of-...
research
06/15/2020

Timely Detection and Mitigation of Stealthy DDoS Attacks via IoT Networks

Internet of Things (IoT) networks consist of sensors, actuators, mobile ...
research
06/24/2020

DDoSNet: A Deep-Learning Model for Detecting Network Attacks

Software-Defined Networking (SDN) is an emerging paradigm, which evolved...
research
03/15/2020

SOM-based DDoS Defense Mechanism using SDN for the Internet of Things

To effectively tackle the security threats towards the Internet of thing...
research
10/02/2019

Machine-Learning Techniques for Detecting Attacks in SDN

With the advent of Software Defined Networks (SDNs), there has been a ra...
research
04/20/2022

ARLIF-IDS – Attention augmented Real-Time Isolation Forest Intrusion Detection System

Distributed Denial of Service (DDoS) attack is a malicious attempt to di...
research
03/07/2020

Machine Learning based Anomaly Detection for 5G Networks

Protecting the networks of tomorrow is set to be a challenging domain du...

Please sign up or login with your details

Forgot password? Click here to reset