Title
DDoS detection and defense mechanism for SDN controllers with K-Means
Abstract
Software-defined networks (SDNs) are key parts of the next generation networks owing to their high programmability and agility that traditional networks lack. However, the SDN controller is vulnerable to Distributed Denial-of-Service (DDoS) attacks. Once the SDN controller was unavailable due to the DDoS attack, all real-time services will be down immediately. Since the advantage of SDN is to process massive network data much faster, we need a real-time detecting algorithm to reduce the impact caused by the attack. To ensure the security of both the users and the SDN, we proposed a detection and defense mechanism against DDoS attacks in Software-defined networking (SDN) environments. The implementation of detection was based on the unbalance in the traffic distribution. The traffic unbalance can be detected by a clustering algorithm such as the K-Means algorithm. Furthermore, we used a Packet_IN message register to filter malicious packets and experimentally evaluated the performance of our scheme in terms of detection accuracy, defense effect, communication delay, and packet loss rate. The results show that our detection method is adaptable to defend against attacks of different scales and types and ensures the least possible decline in the quality of services.
Year
DOI
Venue
2020
10.1109/UCC48980.2020.00062
2020 IEEE/ACM 13th International Conference on Utility and Cloud Computing (UCC)
Keywords
DocType
ISSN
SDN controller,DDoS,K-Means,Packet_IN filter
Conference
2373-6860
ISBN
Citations 
PageRank 
978-1-6654-1563-7
0
0.34
References 
Authors
17
5
Name
Order
Citations
PageRank
Jie Cui115321.52
Jing Zhang2373101.39
Jiantao He300.34
Hong Zhong420833.15
Yao Lu500.34