An SDN ‐based DDoS defense approach using route obfuscation

Mohammad Reza Kalantar Hormozi, Seyed Hossein Erfani · Concurrency and Computation Practice and Experience · 2022

Summary DDoS attack as an attempt to make an online service inaccessible by suppressing it with massive traffic from various sources is a problem that is getting worse by the day, and when customers need to implement DDoS mitigation solutions in their network, they often have to make major changes to the existing network in terms of establishing new protocols or the need to completely redesign the existing network. Software evolution in networks under the name of software‐defined networks is developing and advancing in parallel with traditional networks, and the tendency and migration towards this generation of networks may be considered more and more seriously. Using SDN to encounter DDoS attacks, given its reactive capabilities, brings strategies such as dynamic cyber deception and active defense to minds, against attackers. In this article, we show how to obfuscate the network route to the destination by playing the address in the path and destination of the attacker's request, without understanding them from the heart of the issue by using the capabilities of software‐defined networks and lead DDoS attack flows, and kept the rest of network safe with least effect on topology from this destruction.

Read the paper · More papers on PaperTik