Statistical Approach Based Detection of Distributed Denial of Service Attack in a Software Defined Network

K. Bavani, Mahalingam Ramkumar, G. S. R. Emil Selvan · 2020

Distributed Denial of Service (DDoS) attack is one of the rapidly growing attack that threat the networks to disrupt the network services available to the intended users. The attack is executed by the perpetrator, who creates a malicious data packets and penetrates it into the normal traffic of the targeted network, thereby disrupting the service which is one of the types of botnet attack. DDoS attacks commonly occur in Software Defined Network (SDN) rather than conventional and ad hoc networks. Since the SDN has a centralized control plane which is completely software-based, the perpetrator overload the controller by sending more attack packets to it thereby resulting in a single point of failure. Due to the periodical changes in the fundamental architecture and the physical separation of forwarding plane from the control plane, the SDN becomes more vulnerable to the DDoS attacks. The usage of entropy is proposed to detect DDoS attacks in the existing methods. The proposed method determines the mean entropy using statistical approach and the rate of packet drops to identify the occurrence of DDoS attack at its early stage to prevent the controller from overloading and thus leading to a failure.

Read the paper · More papers on PaperTik