Entropy based DDoS Detection in Software Defined Networks
Giovanni Fioravanti, Mattia Giovanni Spina, Floriano De Rango · 2023
SDN (Software Defined Networking) is a widely used networking technology aiming at decoupling control plane and data plane making network management more flexible and dynamic. This is possible thanks to the programmability feature that characterizes the SDN architecture. Despite all the benefits we can gain from the SDN technique, it is affected by some security issues and vulnerabilities. The main attack it suffers the most is DoS (Denial of Service) and its distributed evolution: DDoS (Distributed DDoS). In this work it is presented a DDoS detection mechanism based on a pillar of Information Theory, namely Shannon Entropy but adopted in SDN environment. To make the detection more accurate it is considered also the concept of packet_in window, which indicates the number of packet_in considered in a certain period of time during communications. The experimental results aim to show the best trade-off between the packet_in window size and the value of the measured entropy in each window leading to an as timeliness as possible detection of DDoS demonstrating that a proper tuning phase of the aforementioned parameters is needed to promptly detect a DDoS attack.