Cyber-Secure SDN: A CNN-Based Approach for Efficient Detection and Mitigation of DDoS Attacks

计算机科学 服务拒绝攻击 计算机安全 软件定义的网络 计算机网络 互联网 万维网
作者
Ashfaq Ahmad Najar,S. Manohar Naik
出处
期刊:Computers & Security [Elsevier]
卷期号:139: 103716-103716
标识
DOI:10.1016/j.cose.2024.103716
摘要

Software Defined Networking (SDN) has become popular due to its flexibility and agility in network management, enabling rapid adaptation to changing business requirements, enhancing network performance, and reducing operational costs. However, the ubiquity of internet-based services has given rise to an alarming increase in cyber-attacks, posing serious threats to the security and stability of modern networks. Among these attacks, Distributed Denial of Service (DDoS) attacks have emerged as one of the most devastating, capable of disrupting critical services. Recent studies have shown that Deep Learning (DL) techniques with Software-defined networking have the potential to mitigate these threats effectively. However, existing solutions suffer from issues such as reliance on pre-defined rules and signatures, computational efficiency, low detection rates, and inefficient notification mechanisms, making them ineffective in detecting DDoS attacks. This paper proposes an efficient approach (BRS + CNN) using Balanced Random Sampling (BRS) and Convolutional Neural Networks (CNNs) to detect DDoS attacks in SDN environments. We have applied various mitigation techniques to mitigate these threats, such as filtering, rate limiting, and iptables rule for blocking spoofed IPs. In addition, we introduce a monitoring system that utilizes rate-limiting to oversee blocked IP addresses, ensuring that legitimate traffic is processed efficiently. The proposed model achieves high performance in binary and multi-classification, with an accuracy of over 99.99% for binary classification and 98.64% for multi-classification. Our proposed DDoS detection system not only detects the attack but also sends detailed contextual information to a designated email address. We compare our model with existing literature and demonstrate its superiority using Area Under The Curve (AUC) analysis. Moreover, we evaluated the efficiency and effectiveness of our proposed DDoS mitigation system by conducting a series of experiments across three distinct scenarios: Attack-Free, Attack-No Mitigation, and Attack-Mitigation. These results demonstrate the robustness of our proposed mitigation system in effectively combating DDoS attacks while also safeguarding the seamless continuity of regular network operations.

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
二147关注了科研通微信公众号
1秒前
腼腆的绝山完成签到,获得积分20
1秒前
哈哈发布了新的文献求助10
1秒前
哈哈12完成签到,获得积分10
2秒前
MW_Zitie发布了新的文献求助10
3秒前
3秒前
3秒前
3秒前
3秒前
hk发布了新的文献求助10
4秒前
4秒前
4秒前
FashionBoy应助科研通管家采纳,获得10
4秒前
4秒前
wanci应助科研通管家采纳,获得10
5秒前
JamesPei应助科研通管家采纳,获得10
5秒前
orixero应助科研通管家采纳,获得10
5秒前
奥奥酱大人完成签到,获得积分10
5秒前
5秒前
6秒前
活泼念双完成签到,获得积分10
6秒前
7秒前
8秒前
Shrine发布了新的文献求助10
8秒前
乐乐应助苹果听枫采纳,获得10
8秒前
哈哈完成签到,获得积分20
8秒前
REBECCA发布了新的文献求助10
8秒前
嘻嘻嘻发布了新的文献求助10
8秒前
9秒前
ograss完成签到,获得积分10
9秒前
MW_Zitie完成签到,获得积分10
9秒前
10秒前
suntee发布了新的文献求助10
10秒前
10秒前
小蘑菇应助hk采纳,获得10
11秒前
宇文书翠完成签到,获得积分10
11秒前
李联洪发布了新的文献求助10
11秒前
11秒前
11秒前
12秒前
高分求助中
(应助此贴封号)【重要!!请各用户(尤其是新用户)详细阅读】【科研通的精品贴汇总】 10000
Lloyd's Register of Shipping's Approach to the Control of Incidents of Brittle Fracture in Ship Structures 1000
BRITTLE FRACTURE IN WELDED SHIPS 1000
Hope Teacher Rating Scale 1000
Entre Praga y Madrid: los contactos checoslovaco-españoles (1948-1977) 1000
Polymorphism and polytypism in crystals 1000
Encyclopedia of Materials: Plastics and Polymers 800
热门求助领域 (近24小时)
化学 材料科学 医学 生物 工程类 纳米技术 有机化学 物理 生物化学 化学工程 计算机科学 复合材料 内科学 催化作用 光电子学 物理化学 电极 冶金 遗传学 细胞生物学
热门帖子
关注 科研通微信公众号,转发送积分 6097094
求助须知:如何正确求助?哪些是违规求助? 7927030
关于积分的说明 16414635
捐赠科研通 5227341
什么是DOI,文献DOI怎么找? 2793817
邀请新用户注册赠送积分活动 1776496
关于科研通互助平台的介绍 1650634