DDOS detection and denial using third party application in SDN

Roshni Mary Thomas, Divya James · 2017

Software Defined Networking(SDN) is a developing area where network managers can manage the network behavior programmatically such as modify, control etc. Using this feature we can empower, facilitate or e network related security applications due to the its capacity to reprogram the data plane at any time. DoS/DDoS attacks are attempt to make controller functions such as online services or web applications unavailable to clients by exhausting computing or memory resources of servers using multiple attackers. A DDoS attacker could produce enormous flooding traffic in a short time to a server so that the services provided by the server get degraded. This will lose of customer support, brand trust etc. To detect this DDoS attack we use a traffic monitoring method iftop in the server as third party application and check the traffic for specific amount of time. iftop is a traffic monitoring tool to find the bandwidth of incoming packets along with the address. Get the traffic into a text file and evaluate the bandwidth od incoming packets with conditions of DDoS attack. If the conditions get satisfied forward the attacker address to the SDN firewall in the controller with the type of incoming packets. Firewall will enter the attacker address in the firewall table along with server address as destination. After that firewall look at the incoming requests to the server if the attacker is still sending or flooding packets, firewall will block the attacker according to the type of of packet forwarding to the server.

Read the paper · More papers on PaperTik