DDoS Attack Detection in OpenFlow Based Networks
Soodeh Asgari, Behzad Akbari · 2022
Since Distributed Denial of Service attacks are one of the main challenges of today’s networks, and the use of software-defined networks as the new technology of today’s networks is rapidly expanding, we decided to research this issue. SDN contains a data plane, control plane, and application plane. The control plane centralized controls multiple switches. Consequently, SDN needs more security. In this study, a new method is presented using the Entropy measure, one of the essential concepts in information theory and, switches flow-table statistics, which is implemented by adding two new components to the controller to collect flow-table information and attack detection. This work has considered three steps to identify DDoS attacks, including TCP SYN, UDP, and ICMP, to minimize the false positive rate and achieve the desired result.