Defending DDoS against Software Defined Networks using Entropy

Rochak Swami, Mayank Dave, Virender Ranga · 2019

Software defined networking (SDN) has gained the attention of many researchers and networking data centers. SDN provides flexibility and programmability to the network which makes it easy to adapt the changes. As SDN controller has a centralized visibility to the complete network topology, it may be targeted by the attackers. By breaking the integration of forwarding and routing rules in a single device, it offers cost-efficient networking services. However, SDN may suffer from various types of Distributed denial of service (DDoS) attacks. DDoS can disturb the complete network functionality by consuming resources and processing power of controller. Some researchers have designed many efficient defense mechanisms recently. In this research work, entropy which is used to compute the randomness of any event is utilized to detect the DDoS attacks. The attack detection module is implemented in POX controller which monitors the statistics of all the incoming flows. The suggested entropy based detection offers to identify the attack in a short duration and gives a fast response.

Read the paper · More papers on PaperTik