A two-stage DDoS attacks detection method in SDN

Yan Li, Bin Y. Qin, Yunsheng Zhang, Wei Nie · 2022

Distributed Denial of Service (DDoS) attacks are one of the dangers of Software Defined Networking (SDN). In order to detect DDoS attacks quickly and accurately, this paper proposes a two-stage DDoS attacks detection method based on SDN, which combines a preliminary detection method based on information entropy and K-Nearest Neighbors (KNN) regression algorithm, and a depth detection method based on Gated Recurrent Unit (GRU). First, the two-stage detection method extracts their necessary data features from the flow table information respectively through the feature extraction module. Second, the preliminary detection module uses the information entropy of the six-tuple as feature vectors to train the KNN regression model. Third, the depth detection module uses the GRU neural network to fully learn the sequence features. Finally, the method proposed in this paper is verified in the experimental environment based on Mininet. When the first-stage preliminary detection module determines that the SDN network environment is suspected of being attacked by DDoS, the second-stage depth detection module is called for further detection. The experimental results demonstrate that the method proposed in this paper can effectively detect DDoS attacks in SDN.

Read the paper · More papers on PaperTik