Port scanning based model to detect Malicious TCP traffic and mitigate its impact in SDN

Jitendra P. Patil, Vrinda Tokekar, Alpana Rajan, Anil Rawat · 2021 2nd International Conference on Secure Cyber Computing and Communications (ICSCCC) · 2021

Software Defined Network (SDN) is a programmable networking model where control plane and data planes are function separately. Controller can be programmed as per the network's functional requirement and can manage several data planes centrally. When a new packet is received by data plane and if no flow entry is existing, it encapsulates the received packet in packet_in message and send it to controller to take appropriate decision. In absence of any source traffic validation mechanism available with default SDN controller, it initiates appropriate action and pushes flow table entry to the data plane switch. This functionality of SDN paradigm unlocks an opportunity to overcharge the controller by using malicious traffic. Detection of source of traffic and mitigation of malicious TCP-SYN traffic precisely has been attempted to be addressed in this paper. We have devised a unique technique named "Port scanning based model to detect Malicious TCP traffic and mitigate its impact in SDN" (PMTS), to validate the source of IPs and source port number of TCP-SYN established connections using customized TCP-FIN packets. Proposed model is easy to implement, effective and faster than standard SYN proxy mechanism. Performance of PMTS model has been evaluated under various scenarios. Results obtained are encouraging and same are compared with state-of-arts models available in the literature.

Read the paper · More papers on PaperTik