A hybrid scheme for detecting and preventing single packet Low-rate DDoS and flooding DDoS attacks in SDN
Wisam H. A Muragaa · 2023
Managing and controlling the network became more agile with Software-Defined Networks (SDN) by means of pulling the intelligence of the network away from the hardware equipment. Although this separation is considered the main advantage of SDN, it makes the SDN structure target for the Distributed Denial of Service (DDoS) attacks that affect the functionalities of the network and made the services completely unavailable to normal users. Detecting one category of DDoS attacks accurately already exists in the literature, but detecting different categories of the attack accurately is still absent. The proposed hybrid scheme in this paper detects the single packet low-rate and flooding DDoS attacks by differentiating the single packets sent to the same destination from different source IP addresses at a constant low rate from packets that are sent at a high rate with a very small elapsed time between these packets. The elapsed time between the successive packets is a new attribute used for detecting the flooding DDoS attacks in SDN. Once the different attack packets are detected, the hybrid scheme prevents Low-rate and flooding DDoS attacks by deleting the flows created by the single packets and dropping the packets with a very small elapsed time from the other flows. Thus, the switch is protected by allowing new flow rules to be installed and new incoming packets to arrive. The results observed from the experiments show that the hybrid scheme achieves a 99.85% accuracy rate with 0 false alarms. Furthermore, the overhead measured is only 29.9% which is positively reflected in the controller’s resources.