Flow count synchronous SDN address hopping technology based on DH-RSA negotiation
Weizhen Lou, Haiai Li, Kaiyu Hu, Min Liu, Qingjiang Dong · 2021
This paper proposes an SDN address hopping algorithm based on flow count synchronization to defend against DDoS attacks. The controller and the client use the DH algorithm to negotiate to generate a hopping address pool, and use RSA to verify the legitimacy of the negotiating parties, ensuring the security of the hopping address pool, and solving the problem that the hopping pattern is easily intercepted and cracked. The flow count is used as an address hopping trigger condition, and the address hopping is selected according to the number of data packets sent in the network, which can quickly respond to large-flow DDoS attacks. Experiments have verified the effectiveness of its defense against DDoS attacks.