A Network Segmentation Architecture for Flow Aggregation and DDoS Mitigation in SDN Using RAPID Flow Rules

计算机科学 服务拒绝攻击 计算机网络 流量(数学) 建筑 流量网络 分割 分布式计算 人工智能 操作系统 互联网 几何学 数学 数学优化 艺术 视觉艺术
作者
. Himanshu,Kalpana Saha,Payel Das,Swades De
标识
DOI:10.1145/3631461.3631561
摘要

Distributed Denial-of-Service (DDoS) attacks have always posed a major threat to networks directly or as a cover for more sophisticated attacks. In recent years, with advances such as the large number of IoT nodes, amplifying platforms like Botnets-as-a-Service, etc., the number of DoS attacks has increased significantly, and the attacks have become more sophisticated. The new paradigm of Software-Defined Networking (SDN) enables a centralized view of the network, which has promising potential for efficient detection and mitigation of such attacks. This modern approach, however, exposes more areas of attack, such as Buffer Saturation, Link Flooding, Flow Table Overflow (FTO), and Controller Saturation. In this paper, we propose a novel, extremely lightweight, simple, yet effective, integrated approach, called Rapid Protection in Dataplane-DDoS (RAPID), for the detection and mitigation of several DoS attacks in SDN scenarios. Our approach couples the centralized view of the SDN networks with network segmentation based on the IP assignment, to generate a novel set of flow rules that can be used to manage the network in a way that allows for a smaller number of overall rules for proactively preventing FTO altogether while generating some novel statistics thereby adding the capability of fast detection and traceback of the origins of attacks to the controller. We evaluate the performance of the proposed scheme - RAPID - with Mininet and Ryu to demonstrate its effectiveness in detecting and mitigating several attacks while maintaining network performance.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
更新
大幅提高文件上传限制,最高150M (2024-4-1)

科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
李健应助yao采纳,获得10
1秒前
懒癌晚期完成签到,获得积分10
1秒前
英姑应助zcone采纳,获得10
1秒前
慕青应助sll采纳,获得10
2秒前
4秒前
重要的小猫咪完成签到,获得积分10
7秒前
青阳完成签到,获得积分10
9秒前
菠菜应助熊仔一百采纳,获得100
11秒前
11秒前
ChenHan应助微微采纳,获得10
13秒前
lvbowen发布了新的文献求助20
13秒前
monkona应助能不能下载啊采纳,获得10
16秒前
lixiang发布了新的文献求助10
17秒前
monkona完成签到,获得积分10
19秒前
20秒前
htk发布了新的文献求助10
21秒前
澳臻白发布了新的文献求助10
23秒前
24秒前
tao发布了新的文献求助10
26秒前
27秒前
28秒前
无花果应助htk采纳,获得10
29秒前
29秒前
uu发布了新的文献求助10
30秒前
31秒前
树枝发布了新的文献求助10
33秒前
含蓄之桃完成签到 ,获得积分10
36秒前
515发布了新的文献求助10
36秒前
星辰大海应助凯文采纳,获得10
37秒前
yiya完成签到,获得积分10
37秒前
40秒前
无花果应助lvbowen采纳,获得10
41秒前
42秒前
gyx发布了新的文献求助10
43秒前
uu完成签到,获得积分10
43秒前
wking完成签到,获得积分20
45秒前
46秒前
46秒前
Cyber_relic完成签到,获得积分10
46秒前
47秒前
高分求助中
BIOLOGY OF NON-CHORDATES 1000
进口的时尚——14世纪东方丝绸与意大利艺术 Imported Fashion:Oriental Silks and Italian Arts in the 14th Century 800
Autoregulatory progressive resistance exercise: linear versus a velocity-based flexible model 550
Zeitschrift für Orient-Archäologie 500
Play from birth to twelve: Contexts, perspectives, and meanings – 3rd Edition 300
Equality: What It Means and Why It Matters 300
A new Species and a key to Indian species of Heirodula Burmeister (Mantodea: Mantidae) 300
热门求助领域 (近24小时)
化学 医学 生物 材料科学 工程类 有机化学 生物化学 物理 内科学 纳米技术 计算机科学 化学工程 复合材料 基因 遗传学 物理化学 催化作用 细胞生物学 免疫学 冶金
热门帖子
关注 科研通微信公众号,转发送积分 3348980
求助须知:如何正确求助?哪些是违规求助? 2975143
关于积分的说明 8667699
捐赠科研通 2655836
什么是DOI,文献DOI怎么找? 1454224
科研通“疑难数据库(出版商)”最低求助积分说明 673254
邀请新用户注册赠送积分活动 663696