Research on DDoS Attack with Learning Ability Detection in SDN Environment

Lipeng Wan, Guiqin Yang · 2022 IEEE 5th Advanced Information Management, Communicates, Electronic and Automation Control Conference (IMCEC) · 2022

Distributed denial of service (DDoS) is one of the most important security threat to software defined network (SDN) of the emerging network architecture. With the development of artificial intelligence technology, DDoS attacks gradually develop towards intelligent direction. Attackers construct attack traffic by imitating normal user traffic characteristics in the network, it enhances the concealment of the attack and has new characteristics compared with the traditional way. In this work, aiming at the new characteristics of the attack with learning ability. Firstly, we construct a DDoS attack with learning ability model. Then, we use a combined machine learning algorithm based on random forest (RF) and support vector machine (SVM) named RF-SVM as detection model. Finally, based on the existing related flow table feature extraction methods, five features are extracted from the flow table of OpenFlow switch in SDN to form feature vectors, so as to better distinguish normal traffic and intelligent attack traffic. The experimental results show that RF-SVM detection model can effectively deal with DDoS attack with learning ability in SDN environment.

Read the paper · More papers on PaperTik