An Effective Defense Against SYN Flooding Attack in SDN
DongHyuk Kim, Phuc Trinh Dinh, Sichul Kevin Noh, Junmin Yi, Minho Park · 2019
Software-Defined Networking (SDN) brings us an opportunity to manage the network more efficiently with the separation of control and data planes. However, SDN is still vulnerable to existing threats from the security point of view. Especially, SYN Flooding Attack, one of the typical Denial of Service attacks, may not only exhaust the resource of a victim but also paralyze the entire SDN network by a large number of control messages between controllers and SDN switches. Although various approaches have been proposed to defend the SYN flooding attack, they still have some drawbacks such as packet processing overload and delay. Therefore, this paper proposes an efficient SYN flooding defense scheme utilizing the TCP Time Out mechanism and Round-Trip Time (RTT). The experiment results show the proposed scheme can defend the attack with low bandwidth occupation between the controller and SDN switches and little computing resources.