Early detection and mitigation of DDoS attacks in software defined networks

One of the security challenges in Software Defined networking (SON) is Distributed denial of service (DDoS) attacks that overwhelm the controller and consume its resources making it unreachable effecting the connectivity throughout the entire network. To detect and mitigate this attack at its early...

Full description

Saved in:
Bibliographic Details
Main Author: Al-Saadi, Mustafa Yahya Zakariya
Format: Thesis
Language:English
Published: 2018
Subjects:
Online Access:http://psasir.upm.edu.my/id/eprint/91946/1/FSKTM%202018%2026%20IR.pdf
http://psasir.upm.edu.my/id/eprint/91946/
Tags: Add Tag
No Tags, Be the first to tag this record!
id my.upm.eprints.91946
record_format eprints
spelling my.upm.eprints.919462022-03-01T02:26:40Z http://psasir.upm.edu.my/id/eprint/91946/ Early detection and mitigation of DDoS attacks in software defined networks Al-Saadi, Mustafa Yahya Zakariya One of the security challenges in Software Defined networking (SON) is Distributed denial of service (DDoS) attacks that overwhelm the controller and consume its resources making it unreachable effecting the connectivity throughout the entire network. To detect and mitigate this attack at its early stages, an entropy-based DDoS attack detection and mitigation algorithm was proposed. The algorithm was written in Python programming language to be implementing on a POX controller. To find the proper detection threshold a series of tests on different scenarios of normal and attack traffic were conducted. If the entropy of the destination JP address falls below the threshold and continue for five consecutive times it is declared as an attack. Then the algorithm was tested with attack on one host and a sub net of six hosts with attack rates of25%, 50% and 75% for the first case and 50%, 75% attack rate for the subnet case. The attack was detected successfully without false negative alarms since the threshold was carefully chosen. Then the next step was to test the mitigation algorithm, the same above scenarios of attack were repeated and the entropy change after the mitigation was observed. The entropy increased and came close to the normal traffic entropy. The proposed method in this project was able to detect and mitigate the attack effectively in its early stages before the intensity escalate to a degree that exhausts the controller. This algorithm was minimal in line code to make it lightweight and made use of the controller's functionality without adding extra computational burden on the controller. 2018-01 Thesis NonPeerReviewed text en http://psasir.upm.edu.my/id/eprint/91946/1/FSKTM%202018%2026%20IR.pdf Al-Saadi, Mustafa Yahya Zakariya (2018) Early detection and mitigation of DDoS attacks in software defined networks. Masters thesis, Universiti Putra Malaysia. Software-defined networking (Computer network technology) Denial of service attacks
institution Universiti Putra Malaysia
building UPM Library
collection Institutional Repository
continent Asia
country Malaysia
content_provider Universiti Putra Malaysia
content_source UPM Institutional Repository
url_provider http://psasir.upm.edu.my/
language English
topic Software-defined networking (Computer network technology)
Denial of service attacks
spellingShingle Software-defined networking (Computer network technology)
Denial of service attacks
Al-Saadi, Mustafa Yahya Zakariya
Early detection and mitigation of DDoS attacks in software defined networks
description One of the security challenges in Software Defined networking (SON) is Distributed denial of service (DDoS) attacks that overwhelm the controller and consume its resources making it unreachable effecting the connectivity throughout the entire network. To detect and mitigate this attack at its early stages, an entropy-based DDoS attack detection and mitigation algorithm was proposed. The algorithm was written in Python programming language to be implementing on a POX controller. To find the proper detection threshold a series of tests on different scenarios of normal and attack traffic were conducted. If the entropy of the destination JP address falls below the threshold and continue for five consecutive times it is declared as an attack. Then the algorithm was tested with attack on one host and a sub net of six hosts with attack rates of25%, 50% and 75% for the first case and 50%, 75% attack rate for the subnet case. The attack was detected successfully without false negative alarms since the threshold was carefully chosen. Then the next step was to test the mitigation algorithm, the same above scenarios of attack were repeated and the entropy change after the mitigation was observed. The entropy increased and came close to the normal traffic entropy. The proposed method in this project was able to detect and mitigate the attack effectively in its early stages before the intensity escalate to a degree that exhausts the controller. This algorithm was minimal in line code to make it lightweight and made use of the controller's functionality without adding extra computational burden on the controller.
format Thesis
author Al-Saadi, Mustafa Yahya Zakariya
author_facet Al-Saadi, Mustafa Yahya Zakariya
author_sort Al-Saadi, Mustafa Yahya Zakariya
title Early detection and mitigation of DDoS attacks in software defined networks
title_short Early detection and mitigation of DDoS attacks in software defined networks
title_full Early detection and mitigation of DDoS attacks in software defined networks
title_fullStr Early detection and mitigation of DDoS attacks in software defined networks
title_full_unstemmed Early detection and mitigation of DDoS attacks in software defined networks
title_sort early detection and mitigation of ddos attacks in software defined networks
publishDate 2018
url http://psasir.upm.edu.my/id/eprint/91946/1/FSKTM%202018%2026%20IR.pdf
http://psasir.upm.edu.my/id/eprint/91946/
_version_ 1726793246264262656
score 13.211869