As the central control hub in the SDN, the SDN controller faces various network threats. DDoS attacks, due to their powerful destructive capabilities, have garnered significant attention from the cybersecurity community. This paper extracts features from real-time attack traffic monitored in an SDN environment, using reversible flow as an important evaluation indicator, while also tracking the reverse flow ratio of the attack traffic. By utilizing this indicator and conducting user behavior statistical analysis of the source IPs of the attack traffic, the system assesses the malicious level of the attack traffic and applies mitigation measures accordingly. This results in a detection and mitigation system capable of autonomously and quickly identifying DDoS attacks. Experimental results show that this system can effectively and swiftly detect and mitigate DDoS attacks in an SDN environment. Additionally, using reversible flow as a characteristic value results in higher accuracy, enhancing the detection and handling capabilities for DDoS attacks.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A DDoS Attack Detection and Mitigation System in SDN

  • Xinyue Zhang,
  • Yun Song,
  • Cunqiang Ge

摘要

As the central control hub in the SDN, the SDN controller faces various network threats. DDoS attacks, due to their powerful destructive capabilities, have garnered significant attention from the cybersecurity community. This paper extracts features from real-time attack traffic monitored in an SDN environment, using reversible flow as an important evaluation indicator, while also tracking the reverse flow ratio of the attack traffic. By utilizing this indicator and conducting user behavior statistical analysis of the source IPs of the attack traffic, the system assesses the malicious level of the attack traffic and applies mitigation measures accordingly. This results in a detection and mitigation system capable of autonomously and quickly identifying DDoS attacks. Experimental results show that this system can effectively and swiftly detect and mitigate DDoS attacks in an SDN environment. Additionally, using reversible flow as a characteristic value results in higher accuracy, enhancing the detection and handling capabilities for DDoS attacks.