SDN-Based Intrusion Detection System for Early Detection and Mitigation of DDoS Attacks

SDN-Based Intrusion Detection System for Early Detection and Mitigation of DDoS Attacks
复制标题

DOI:
10.3390/info10030106
复制
发表时间:
2019-03-08
期刊:
影响因子:
3.1
通讯作者:
Serrao, Carlos
Serrao, Carlos
中科院分区:
其他
文献类型:
--
作者:
Manso, Pedro;Moura, Jose;Serrao, Carlos

文献摘要

被引文献

相似文献

本文讨论了物联网(IoT)新兴范式中网络设备引入的相关网络安全漏洞,以及减轻某些类型的分布式拒绝服务(DDoS)攻击的负面影响的迫切需要,这些攻击试图探索这些安全漏洞。我们设计并实现了一个软件定义的入侵检测系统(IDS),该系统能够在攻击源处反应性地削弱攻击,确保网络基础设施的“正常运行”。我们的建议包括一个IDS,它可以自动检测多种DDoS攻击,然后当检测到攻击时,它会通知软件定义网络(SDN)控制器。当前提案还将一些方便的流量转发决策从SDN控制器下载到网络设备。评估结果表明,我们的建议及时检测基于DDoS的几种类型的网络攻击,减轻其对网络性能的负面影响,并确保正常流量的正确数据传输。我们的工作揭示了在网络基础设施的抽象视图上的编程相关性,以及时检测僵尸网络利用,从源头上减轻恶意流量,并保护良性流量。
The current paper addresses relevant network security vulnerabilities introduced by network devices within the emerging paradigm of Internet of Things (IoT) as well as the urgent need to mitigate the negative effects of some types of Distributed Denial of Service (DDoS) attacks that try to explore those security weaknesses. We design and implement a Software-Defined Intrusion Detection System (IDS) that reactively impairs the attacks at its origin, ensuring the "normal operation" of the network infrastructure. Our proposal includes an IDS that automatically detects several DDoS attacks, and then as an attack is detected, it notifies a Software Defined Networking (SDN) controller. The current proposal also downloads some convenient traffic forwarding decisions from the SDN controller to network devices. The evaluation results suggest that our proposal timely detects several types of cyber-attacks based on DDoS, mitigates their negative impacts on the network performance, and ensures the correct data delivery of normal traffic. Our work sheds light on the programming relevance over an abstracted view of the network infrastructure to timely detect a Botnet exploitation, mitigate malicious traffic at its source, and protect benign traffic.