FloodKnight: an intelligent DDoS defense scheme to combat attacks near attack entry points
摘要
Software-Defined Network facilitates the real-time monitoring and quick re-configuration of the network that was difficult in the traditional networks. These facilities are promising for the mitigation of DDoS attacks. With appropriate identification patterns of Distributed Denial of Service (DDoS) attacks and detection scheme to analyze the network behavior, these attacks could be detected and suppressed in infant stages. In this paper, a system model FloodKnight integrated with SDN controller is proposed to detect DDoS attacks. FloodKnight analyzes the network behavior based on a proposed feature set, which is further compared with one of the existing popular feature sets. FloodKnight utilizes Radial Basis Function network with Particle Swarm Optimization optimized learning to detect DDoS attacks that provide accurate classification of DDoS attacks and legitimate traffic. The FloodKnight system model attempts to identify the network’s attack entry points to mitigate the attacks near the attack sources. For Identifying the network’s attack entry points, a port-based source traceback scheme is proposed in this paper. The FloodKnight model’s efficiency is verified by its real-time implementation with the Mininet network simulator and Floodlight SDN controller. The proposed system model efficiently classifies DDoS attacks in their early stages and combats the attacks near attack sources to minimize the impact of the attack on legitimate communication.