NGS: Mitigating DDoS Attacks using SDN-based Network Gate Shield

Mohamad Suhel Dalati, Weizhi Meng, Wei-Yang Chiu · 2021 IEEE Global Communications Conference (GLOBECOM) · 2021

The Internet of Things (IoT) implements a tremendous environment of extensive data streams, whereby any suspicious activities should be detected to safeguard systems' reliability and availability. Distributed Denial of Service (DDoS) attack is a major threat on computer networks, in which an attacker can send huge traffic with multiple IP addresses or machines. In this work, we focus on detecting DDoS attacks, and design Network Gate Shield (NGS), a tool that works on SDN architecture based on the RYU controller. It can examine the traffic trustworthiness, and then determine whether the current traffic is normal based on packet specification, such as the average packet size and the packet per-sec threshold. In the evaluation with an emulated environment, our experimental results indicate that NGS is viable and effective in mitigating DDoS traffic compared with several similar detection approaches.

Read the paper · More papers on PaperTik