Performance and Features: Mitigating the Low-Rate TCP-Targeted DoS Attack via SDN

Performance and Features: Mitigating the Low-Rate TCP-Targeted DoS Attack via SDN
复制标题

性能和特性:通过 SDN 缓解针对低速率 TCP 的 DoS 攻击

DOI:
10.1109/jsac.2021.3126053
复制
发表时间:
2022-01
影响因子:
16.4
通讯作者:
Qin Zheng
Qin Zheng
中科院分区:
计算机科学1区
文献类型:
--
作者:
Tang Dan;Yan Yudong;Zhang Siqi;Chen Jingwen;Qin Zheng

文献摘要

相似文献

软件定义网络(SDN)是一种新兴的网络架构。解耦的数据和控制平面为高效的网络管理提供了可编程性。但是,SDN的集中控制方式也暴露出独特的漏洞。低速率拒绝服务攻击(Low-rate Denial of Service, LDoS)具有周期性和隐蔽性等特点,攻击率低于普通DDoS攻击,是SDN面临的严重威胁之一。在本文中,我们提出了一个轻量级的实时框架性能和特征(P&F)来检测和减轻SDN的LDoS攻击。我们在SDN中实现LDoS攻击,利用OpenFlow提取流量特征,并将特征分为两类。P&F通过分析正常流量在攻击状态下的性能(P),基于机器学习判断ddos攻击是否生效。同时,P&F基于时频分析,根据LDoS攻击的流量特征(F)定位攻击源和攻击对象。P&F根据检测和定位结果设置相应的缓解方案。实验结果表明,P&F检测LDoS攻击具有较高的检测率和较低的误报率。P&F可以部署在控制器上,以较低的系统成本实现实时攻击检测和缓解,可以有效防御ddos攻击。
Software-Defined Networking (SDN) is an emerging network architecture. The decoupled data and control plane provides programmability for efficient network management. However, the centralized control mode of SDN also exposes unique vulnerabilities. Low-rate Denial of Service (LDoS) has a lower attack rate than ordinary DDoS attacks with the characteristics of periodicity and concealment, which is among one of the severe threats to SDN. In this paper, we propose a lightweight, real-time framework Performance and Features (P&F) to detect and mitigate LDoS attacks with SDN. We implement LDoS attacks in SDN, extract traffic features with OpenFlow, and classify the features into two categories. By analyzing the performance (P) of normal traffic under attack state, P&F determines whether LDoS attacks take effect based on machine learning. Meanwhile, P&F tries to locate attack sources and victims according to flow features (F) of LDoS attacks based on time-frequency analysis. According to detection and locating results, P&F sets corresponding mitigation schemes. Experimental results show that P&F has a high detection rate and low false positive rate for detecting LDoS attacks. P&F can deploy on controllers to achieve real-time attack detection and mitigation with low system cost, which can defend against LDoS attacks effectively.