DDoS Attack Detection in Software Defined Networks
摘要
Distribute Denial of service (DDoS) attacks present critical challenge to network administrator to protect sensitive information, network resources and digital documents. Undetected DDoS attacks leads to service disruption and financial losses to an organization. The severity, scale and complexity of present day DDoS attacks necessitates the development of effective DDoS attack detection techniques. A promising architectural approach that enables central management over network services and makes it easier to integrate advanced security measures is Software-Defined Networking (SDN). Since most of previous researches carried out till date, only focus on traditional network DDoS attack detection methods, this review paper attempts to provide an extensive investigation and evaluation of various DDoS detection techniques for SDN. This paper begins with an overview and characteristics of various DDoS attacks, emphasizing how they could affect SDN-based networks if not mitigated timely. Subsequently it surveys the state of the art DDoS attack detection techniques such as threshold-based, machine learning-based, and flow-based techniques. We have also presented the challenges of DDoS attack detection in the SDN paradigm, including the need for real-time packet analysis and efficient resource allocation. In nutshell, this review article serves as a comprehensive resource for scholars, network administrators, and regulatory bodies.