Early Detection and Mitigation of DoS Attacks in SDN Controller

N Saritakumar, K. V. Anusuya · 2022

Software-Defined Networks (SDN), a single authority-managed network, vulnerable to various attacks, demands high security to its Controller. The Denial of Service (DoS) attack deactivates the network controller by flooding packets. Hence, two solutions are proposed for the early detection of DoS attacks: the Congestion control-based algorithm with a rate-limited queue mechanism and the Entropy-based algorithm with adaptive threshold estimation. The first proposal involves the pre-detection of DoS attacks at the early stages in SDN layers to prevent network congestion. The continuous monitoring of SDN switch ports identifies the repeated request of an IP/MAC address beyond a specified threshold, estimated through the CPU utilization factor. For the confirmed attack, the threat packets are queued separately and rate-limited. The second proposal detects low-level attacks by computing entropy and adaptive threshold estimation. The mitigation process either blocks or redirects the packets to the virtual host. The performance of the proposed algorithms in POX-SDN controllers is analyzed using Mininet.

Read the paper · More papers on PaperTik