Packet in Message Based DDoS Attack Detection in SDN Network Using OpenFlow

Research output: Chapter in Book/Report/Conference proceedingConference contribution

27 Citations (Scopus)

Abstract

Using the OpenFlow protocol, the virtual network technology SDN (Software Defined Network) is now widely used. In recent years, the number of DDoS attacks has been increasing year by year. To detect DDoS attacks in SDN, data recorded in the flow table in OpenFlow switch is analyzed and various detection methods are submitted. However, SDN centrally manages communication within the network, when detecting DDoS (Distributed Denial of Service) attacks. This creates a heavy processing load, and the processing load of the OpenFlow controller must be considered. In this paper, in order to reduce the processing load of the controller, we do not collect data of the flow table, extract three features from the Packet In message for communication between the controller and the switch, and perform real-time attack detection. Furthermore, to avoid stringent detection time intervals, triggers will be added before detection to realize light and dynamic DDoS attacks detection.

Original languageEnglish
Title of host publicationProceedings - 2017 5th International Symposium on Computing and Networking, CANDAR 2017
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages522-528
Number of pages7
ISBN (Electronic)9781538620878
DOIs
Publication statusPublished - Jul 2 2017
Event5th International Symposium on Computing and Networking, CANDAR 2017 - Aomori, Japan
Duration: Nov 19 2017Nov 22 2017

Publication series

NameProceedings - 2017 5th International Symposium on Computing and Networking, CANDAR 2017
Volume2018-January

Other

Other5th International Symposium on Computing and Networking, CANDAR 2017
Country/TerritoryJapan
CityAomori
Period11/19/1711/22/17

All Science Journal Classification (ASJC) codes

  • Artificial Intelligence
  • Computer Networks and Communications
  • Hardware and Architecture

Fingerprint

Dive into the research topics of 'Packet in Message Based DDoS Attack Detection in SDN Network Using OpenFlow'. Together they form a unique fingerprint.

Cite this