Detecting DDoS Attacks on SDN Data Plane with Machine Learning
Ranyelson Neres Carvalho, Lucas Rodrigues Costa, Jacir Luiz BORDIM, Eduardo Alchieri · 2021
Distributed denial of service (DDoS) attacks challenge software-defined networks (SDN), primarily due to vulnerabilities present in the separation between the control and data planes. The control plane maintains continuous communication with the data plane switches to direct traffic according to forwarding policies. Although the literature presents various solutions to detect DDoS attacks, most of them concentrate on the control plane. The controller facilitates automated network management, making it easier to integrate and administer applications. On the other hand, the development of security solutions on the control plane imposes an additional load on the controller’s duties. As an alternative to this problem, the research community proposed security solutions adapted to work on the data plane. However, due to the complexity of acting in this layer, the proposed solutions are restricted to statistical analysis of the network flow. This work proposes DataPlane-ML, a machine learning (ML) solution that acts on the data plane to detect DDoS attacks. To realize the use of ML techniques at the data plane, DataPlane-ML makes use of white box switches enhanced with P4 constructs to handle input flow and ML libraries to run ML models. This strategy allows the use of ML techniques on the data plane to provide more elaborated solutions that operate close to the input flow, reducing the impact on the SDN controller. The proposed DataPlane-ML was evaluated using the KNN, SVM and RF algorithms to detect DDoS attacks on real network traces. The experimental results show that DataPlane-ML is ≈23% faster than statistical-based solutions while providing better accuracy and similar CPU usage.