Software defined networking-based one-packet DDoS mitigation architecture
Trương Thu Hương, Nguyen Huu Thanh · 2017
Nowadays, Distributed Denial of Service (DDoS) attacks get the most attention since volumetric attacks saturate company's networks and associated server infrastructure. In fact, DDoS can occur weekly or daily in a network but many organizations have no systems in place to monitor DDoS traffic so as to be aware if their networks are being attacked. Within that context, we propose to develop an architecture that enables a network a capacity of monitoring traffic on the fly and flexibly applying various detection and mitigation methods in order to reduce DDoS impact on the system shortly after it has happened. We also propose a SDN One-packet DDoS Mitigation (SODM) scheme with an Openflow switch functioning as a gateway to protect the inner server infrastructure. We also analyze Internet traffic to understand its common nature during attack and normal time. Knowledge of the traffic characteristics and the way to derive attack indicators are a critical input for the detection mechanism to work. The defense solution performance is evaluated to be able to cope with DDoS in small real time-scale with an acceptable false positive rate of ~ 6%.