Combination of KNN and Time Series to Detect DDoS Attacks in Software-Defined Networks
Ching-Hsiang Hsu, Cheng‐Yuan Ku, Humble Po-Ching Hwang · 2019
For Distributed Denial of Service (DDoS) attacks, they can easily make networking system out of resources due to responses to malicious hosts and then the system cannot provide normal service any more. Even the new architecture of Software Defined Networks (SDN) is getting prevailing, it still suffers from this type of attacks. When the malicious hosts launch DDoS in SDN, more serious consequences may happen. When the central controller is attacked, the overall system can crush. In order to prevent DDoS attacks from malicious hosts, this paper proposes a method with two modules. First, we use time series to predict regular flows from historic data. Second, we adopt k-nearest neighbors (KNN) to detect whether arriving packets are normal or not. Finally, we combine these two results to calculate the probability of being attacked. Using this proposed method, we can not only detect attacks but also prevent attacks by adding malicious hosts in the blacklist.