Cyber-Secure SDN: A CNN-Based Approach for Efficient Detection and Mitigation of DDoS Attacks

计算机科学 服务拒绝攻击 计算机安全 软件定义的网络 计算机网络 互联网 万维网
作者
Ashfaq Ahmad Najar,S. Manohar Naik
出处
期刊:Computers & Security [Elsevier BV]
卷期号:139: 103716-103716
标识
DOI:10.1016/j.cose.2024.103716
摘要

Software Defined Networking (SDN) has become popular due to its flexibility and agility in network management, enabling rapid adaptation to changing business requirements, enhancing network performance, and reducing operational costs. However, the ubiquity of internet-based services has given rise to an alarming increase in cyber-attacks, posing serious threats to the security and stability of modern networks. Among these attacks, Distributed Denial of Service (DDoS) attacks have emerged as one of the most devastating, capable of disrupting critical services. Recent studies have shown that Deep Learning (DL) techniques with Software-defined networking have the potential to mitigate these threats effectively. However, existing solutions suffer from issues such as reliance on pre-defined rules and signatures, computational efficiency, low detection rates, and inefficient notification mechanisms, making them ineffective in detecting DDoS attacks. This paper proposes an efficient approach (BRS + CNN) using Balanced Random Sampling (BRS) and Convolutional Neural Networks (CNNs) to detect DDoS attacks in SDN environments. We have applied various mitigation techniques to mitigate these threats, such as filtering, rate limiting, and iptables rule for blocking spoofed IPs. In addition, we introduce a monitoring system that utilizes rate-limiting to oversee blocked IP addresses, ensuring that legitimate traffic is processed efficiently. The proposed model achieves high performance in binary and multi-classification, with an accuracy of over 99.99% for binary classification and 98.64% for multi-classification. Our proposed DDoS detection system not only detects the attack but also sends detailed contextual information to a designated email address. We compare our model with existing literature and demonstrate its superiority using Area Under The Curve (AUC) analysis. Moreover, we evaluated the efficiency and effectiveness of our proposed DDoS mitigation system by conducting a series of experiments across three distinct scenarios: Attack-Free, Attack-No Mitigation, and Attack-Mitigation. These results demonstrate the robustness of our proposed mitigation system in effectively combating DDoS attacks while also safeguarding the seamless continuity of regular network operations.

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
半枝桃完成签到,获得积分10
刚刚
可爱的函函应助xx采纳,获得10
1秒前
long发布了新的文献求助10
1秒前
2秒前
哎呦呦完成签到,获得积分10
3秒前
欧阳振完成签到,获得积分10
3秒前
lbc发布了新的文献求助10
3秒前
烟花应助11MZ采纳,获得10
3秒前
科研通AI6.4应助胖虎采纳,获得10
3秒前
3秒前
迷路胡萝卜完成签到,获得积分10
4秒前
4秒前
4秒前
Mercy发布了新的文献求助10
5秒前
sylvia发布了新的文献求助10
5秒前
Suliove完成签到,获得积分10
5秒前
6秒前
阳光寒荷发布了新的文献求助10
6秒前
深情安青应助long采纳,获得10
7秒前
星辰大海应助没有采纳,获得10
7秒前
8秒前
8秒前
123456789发布了新的文献求助10
8秒前
Owen应助1900tdlemon采纳,获得10
10秒前
10秒前
Aimee发布了新的文献求助10
10秒前
11秒前
lian发布了新的文献求助10
11秒前
11秒前
吴红波完成签到,获得积分10
11秒前
11MZ发布了新的文献求助10
11秒前
Spy_R完成签到,获得积分10
13秒前
13秒前
13秒前
14秒前
DoctorX完成签到,获得积分10
14秒前
woaikeyan完成签到 ,获得积分10
15秒前
nnhhl发布了新的文献求助10
15秒前
英俊的铭应助dyy采纳,获得10
15秒前
隐形曼青应助学无止境采纳,获得10
15秒前
高分求助中
The Wiley Blackwell Companion to Diachronic and Historical Linguistics 3000
Standards for Molecular Testing for Red Cell, Platelet, and Neutrophil Antigens, 7th edition 1000
HANDBOOK OF CHEMISTRY AND PHYSICS 106th edition 1000
ASPEN Adult Nutrition Support Core Curriculum, Fourth Edition 1000
Signals, Systems, and Signal Processing 610
脑电大模型与情感脑机接口研究--郑伟龙 500
GMP in Practice: Regulatory Expectations for the Pharmaceutical Industry 500
热门求助领域 (近24小时)
化学 材料科学 医学 生物 纳米技术 工程类 有机化学 化学工程 生物化学 计算机科学 物理 内科学 复合材料 催化作用 物理化学 光电子学 电极 细胞生物学 基因 无机化学
热门帖子
关注 科研通微信公众号,转发送积分 6296266
求助须知:如何正确求助?哪些是违规求助? 8113717
关于积分的说明 16982766
捐赠科研通 5358394
什么是DOI,文献DOI怎么找? 2846844
邀请新用户注册赠送积分活动 1824112
关于科研通互助平台的介绍 1679015