Med-DDoS-SDN: A Kafka Streams-Based Distributed Approach for Protecting Healthcare SDN Environments Against DDoS Attacks
摘要
The healthcare sector, dealing with vast and sensitive data, faces an ever-expanding need for efficient data management and security. Automated healthcare devices generate crucial information, and Software-Defined Networking (SDN) has become integral to healthcare systems due to resource efficiency, robust monitoring, and centralized control. However, in this data-centric environment, SDNs are vulnerable to various cyber threats, including Distributed Denial of Service (DDoS) attacks and probing attempts. These attacks can harm network performance, potentially endangering lives, especially with the rise of portable healthcare integrating mobile services and programmable devices. This article proposes a Kafka Streams-based distributed approach to protect SDN-based healthcare systems from DDoS attacks, named Med-DDoS-SDN. The Med-DDoS-SDN comprises two modules: (i) Real-time Attack Traffic Classification Module (RACM) and (ii) Preprocessed Data Storage Module (PDSM). The RACM categorizes incoming network traffic into four real-time classes. PDSM collects 21 essential features with outcomes into the Hadoop Distributed File System (HDFS) to maintain the classification model with the range samples. Med-DDoS-SDN is formulated and verified using the CICDDoS2019 dataset. The average classification accuracy of the distributed Med-DDoS-SDN solution stands at 92.75%.