Towards Applying IPSec between Edge Switches and End Users to Counter DDoS Attacks in SDNs
Abdullah Soliman Alshra’a, Jochen Seitz · 2021
Software-Defined Networking (SDN) is a new networking paradigm with many advantages compared to traditional networks, such as reliability, scalability, and flexibility. However, SDN inherits some vulnerabilities from traditional networks and even shows new properties that malicious users might exploit as vulnerable aspects. In this paper, a novel solution is introduced based on the notion of the IP Security protocol (IPSec) and an adaptive threshold algorithm to counter Distributed Denial of Service (DDoS) attacks and freeloading attacks. The simulation results show the ability of the proposed countermeasure to prevent these attacks by distinguishing between benign and malicious users, which shows a notable enhancement compared to previous approaches.