Cyber-Secure SDN: A CNN-Based Approach for Efficient Detection and Mitigation of DDoS Attacks

计算机科学 服务拒绝攻击 计算机安全 软件定义的网络 计算机网络 互联网 万维网
作者
Ashfaq Ahmad Najar,S. Manohar Naik
出处
期刊:Computers & Security [Elsevier BV]
卷期号:139: 103716-103716
标识
DOI:10.1016/j.cose.2024.103716
摘要

Software Defined Networking (SDN) has become popular due to its flexibility and agility in network management, enabling rapid adaptation to changing business requirements, enhancing network performance, and reducing operational costs. However, the ubiquity of internet-based services has given rise to an alarming increase in cyber-attacks, posing serious threats to the security and stability of modern networks. Among these attacks, Distributed Denial of Service (DDoS) attacks have emerged as one of the most devastating, capable of disrupting critical services. Recent studies have shown that Deep Learning (DL) techniques with Software-defined networking have the potential to mitigate these threats effectively. However, existing solutions suffer from issues such as reliance on pre-defined rules and signatures, computational efficiency, low detection rates, and inefficient notification mechanisms, making them ineffective in detecting DDoS attacks. This paper proposes an efficient approach (BRS + CNN) using Balanced Random Sampling (BRS) and Convolutional Neural Networks (CNNs) to detect DDoS attacks in SDN environments. We have applied various mitigation techniques to mitigate these threats, such as filtering, rate limiting, and iptables rule for blocking spoofed IPs. In addition, we introduce a monitoring system that utilizes rate-limiting to oversee blocked IP addresses, ensuring that legitimate traffic is processed efficiently. The proposed model achieves high performance in binary and multi-classification, with an accuracy of over 99.99% for binary classification and 98.64% for multi-classification. Our proposed DDoS detection system not only detects the attack but also sends detailed contextual information to a designated email address. We compare our model with existing literature and demonstrate its superiority using Area Under The Curve (AUC) analysis. Moreover, we evaluated the efficiency and effectiveness of our proposed DDoS mitigation system by conducting a series of experiments across three distinct scenarios: Attack-Free, Attack-No Mitigation, and Attack-Mitigation. These results demonstrate the robustness of our proposed mitigation system in effectively combating DDoS attacks while also safeguarding the seamless continuity of regular network operations.

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
和谐伟泽完成签到 ,获得积分10
刚刚
一期一会完成签到,获得积分10
1秒前
555完成签到,获得积分10
1秒前
3秒前
老实莫言完成签到,获得积分10
6秒前
6秒前
夜乡晨完成签到 ,获得积分10
7秒前
syt发布了新的文献求助10
8秒前
9秒前
凡凡完成签到,获得积分10
9秒前
11秒前
阳光绿柏完成签到,获得积分10
11秒前
11秒前
城北徐公发布了新的文献求助10
14秒前
15秒前
mikasa发布了新的文献求助10
18秒前
英姑应助Meng采纳,获得10
18秒前
科研通AI2S应助爬不起来采纳,获得10
19秒前
东都哈士奇完成签到,获得积分10
20秒前
Y....完成签到,获得积分10
21秒前
清瓷发布了新的文献求助10
25秒前
27秒前
27秒前
27秒前
27秒前
张嘻嘻应助科研通管家采纳,获得30
27秒前
英姑应助科研通管家采纳,获得10
27秒前
27秒前
27秒前
27秒前
6666应助科研通管家采纳,获得10
27秒前
27秒前
情怀应助科研通管家采纳,获得10
28秒前
Owen应助科研通管家采纳,获得10
28秒前
大模型应助科研通管家采纳,获得10
28秒前
Jasper应助科研通管家采纳,获得10
28秒前
苹果千筹给明理绿海的求助进行了留言
28秒前
爬不起来完成签到,获得积分10
29秒前
ASHhan111完成签到,获得积分0
30秒前
frank完成签到,获得积分10
31秒前
高分求助中
(应助此贴封号)【重要!!请各用户(尤其是新用户)详细阅读】【科研通的精品贴汇总】 10000
PowerCascade: A Synthetic Dataset for Cascading Failure Analysis in Power Systems 2000
Various Faces of Animal Metaphor in English and Polish 800
Signals, Systems, and Signal Processing 610
Photodetectors: From Ultraviolet to Infrared 500
On the Dragon Seas, a sailor's adventures in the far east 500
Yangtze Reminiscences. Some Notes And Recollections Of Service With The China Navigation Company Ltd., 1925-1939 500
热门求助领域 (近24小时)
化学 材料科学 医学 生物 纳米技术 工程类 有机化学 化学工程 生物化学 计算机科学 物理 内科学 复合材料 催化作用 物理化学 光电子学 电极 细胞生物学 基因 无机化学
热门帖子
关注 科研通微信公众号,转发送积分 6348927
求助须知:如何正确求助?哪些是违规求助? 8164067
关于积分的说明 17176151
捐赠科研通 5405398
什么是DOI,文献DOI怎么找? 2861990
邀请新用户注册赠送积分活动 1839786
关于科研通互助平台的介绍 1689033