错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

FloodKnight: an intelligent DDoS defense scheme to combat attacks near attack entry points

  • Neelam Dayal,
  • Shashank Srivastava

摘要

Software-Defined Network facilitates the real-time monitoring and quick re-configuration of the network that was difficult in the traditional networks. These facilities are promising for the mitigation of DDoS attacks. With appropriate identification patterns of Distributed Denial of Service (DDoS) attacks and detection scheme to analyze the network behavior, these attacks could be detected and suppressed in infant stages. In this paper, a system model FloodKnight integrated with SDN controller is proposed to detect DDoS attacks. FloodKnight analyzes the network behavior based on a proposed feature set, which is further compared with one of the existing popular feature sets. FloodKnight utilizes Radial Basis Function network with Particle Swarm Optimization optimized learning to detect DDoS attacks that provide accurate classification of DDoS attacks and legitimate traffic. The FloodKnight system model attempts to identify the network’s attack entry points to mitigate the attacks near the attack sources. For Identifying the network’s attack entry points, a port-based source traceback scheme is proposed in this paper. The FloodKnight model’s efficiency is verified by its real-time implementation with the Mininet network simulator and Floodlight SDN controller. The proposed system model efficiently classifies DDoS attacks in their early stages and combats the attacks near attack sources to minimize the impact of the attack on legitimate communication.