Entropy-based DDoS Attack Detection in SDN using Dynamic Threshold

Zahra Hemmati, Ghasem Mirjalily, Zahra Mohtajollah · 2021

The centralized structure of software defined networks makes them vulnerable to distributed denial of service attacks. Given that these attacks can easily destroy the computational and communicational resources of controller and switches, they make the network fail in a short time. Hence, it is vital to protect the controller. Utilizing the unique features of software defined networks, this paper propounds an effective method to detect distributed denial of services attacks. For this purpose, entropy was used to detect attacks. Furthermore, this method utilizes a dynamic threshold instead of a static one to distinguish between normal and attack traffic. The dynamic threshold heightens the accuracy of attack detection in the proposed algorithm to 98% on average while the accuracy in the benchmark algorithm using entropy and the static threshold is 96%.

Read the paper · More papers on PaperTik