학술논문

Mitigation of DDoS Attack in SDN using Table Miss-entry
Document Type
Conference
Source
2022 4th International Conference on Circuits, Control, Communication and Computing (I4C) Circuits, Control, Communication and Computing (I4C), 2022 4th International Conference on. :6-11 Dec, 2022
Subject
Communication, Networking and Broadcast Technologies
Components, Circuits, Devices and Systems
Computing and Processing
Robotics and Control Systems
Intrusion detection
Denial-of-service attack
Software defined networking
Computer crime
Centralized control
Software Defined networks
DDoS Attack
Table miss-entry
IDS (Intrusion Detection System)
SNORT
Language
Abstract
SDNs or Software Defined Networks differ from traditional networks due to the separation of the control and data plane. However, it is this centralized control that makes SDNs prone to DDoS attacks if the network operations are not addressed properly. One of the ways to cause DDoS is through an influx of control messages (PACKET_IN); due to the Flow Table Miss-entry rule, such attacks can be carried out rather easily. In this work, the aim is to look at DDoS attacks targeting the controller by generating large PACKET_IN traffic from switches and overwhelming them with large amounts of new requests. Such an attack causes the controller to not be able to serve even legitimate traffic. This research looks at effective detection and mitigation techniques utilizing the SNORT IDS that may be used to prevent such attacks from causing any significant harm to the network.