Layer Based Firewall Application for Detection and Mitigation of Flooding Attack on SDN Network

Layer Based Firewall Application for Detection and Mitigation of Flooding Attack on SDN Network
复制标题

DOI:
10.55708/js0105010
复制
发表时间:
2022-05
期刊:
Journal of Engineering Research and Sciences
影响因子:
--
通讯作者:
Yubaraj Gautam;Kazuhiko Sato;B. P. Gautam
Yubaraj Gautam;Kazuhiko Sato;B. P. Gautam
中科院分区:
其他
文献类型:
--
作者:
Yubaraj Gautam;Kazuhiko Sato;B. P. Gautam

文献摘要

相似文献

软件定义网络(SDN)是一种新兴的网络技术,它可以通过编程技术在数据平面上增加控制平面。然而,要实现安全通信,需要解决一些安全挑战。洪泛攻击是近几十年来互联网上最常见的威胁之一,也是SDN网络中具有挑战性的问题。针对这些问题,我们提出了一种基于多阶段包过滤技术开发的新型防火墙应用,以提供洪泛攻击防御系统和基于层的包检测系统。在本研究中,我们主要使用两个阶段来检测洪泛攻击和缓解洪泛数据包。第一阶段是识别攻击,第二阶段是识别攻击者的信息,并根据基于层的包头实体进行攻击。该系统包含两个安全实体来识别洪泛攻击,一个是通过测量数据包大小,另一个是通过对数据包流进行计数。我们使用数据包流的详细信息来控制流,并识别是否发生了攻击。此外,为了识别攻击者的信息,我们使用了基于层(第2层到第4层)的数据包头实体,并使用了多表架构。该方案针对不同的攻击场景进行了测试,成功地降低了SDN网络中基于卷的批量洪泛攻击和无限包洪泛攻击的流量。
: Software-Defined Networking (SDN) is an emerging Network technology that can augment the data plane with control plane by using programming technique. However, there are a numbers of security challenges which are required to address to achieve secured communication. Flooding attack is one of the most common threats on the internet for the last decades which is becoming the challenging issues in SDN networks too. To address these issues, we proposed a novel firewall application developed based on the multiple stages of packets filtering technique to provide flooding attack prevention system and layer-based packets detection system. In this research, we are using two main stages to detect the flooding attack and mitigate the flooding packets. The first stage is to identify the attacks and , the second stage is to identify the attacker’s information and act them based on layer-based packet header entity. The system contains two security entities to identify the flooding attacks, one is by measuring the packet size, and the other is by counting the packets flow. We used the details of packets flow to control over the flow and to identify the attacks being occurred or not. Along with, to identify the attacker’s information, we used layers (layer 2 to layer 4) based packet header entities by using multi-table architecture. The proposed solution was tested for different attack scenarios and successfully reduced the flow of volume-based bulk-size flooding attack and infinite packets flooding attack in SDN network.