Renyi Entropy-based DDoS Attack Detection in SDN-based Networks
Haiyan Zhang, Long Zhou, Jiangang Lei · 2023
Software-defined network (SDN) decouples the control plane and the data plane of the network, and the controller itself becomes a target for network attacks. Attackers can launch a distributed denial-of-service (DDoS) attack to render the controller ineffective and compromise network security. To differentiate DDoS attacks in SDN, Renyi entropy is utilized to detect anomalous data. This method involves gathering data packets at the controller, computing Renyi entropy based on the source and destination IP addresses, then detecting abnormal traffic by setting a predetermined threshold. Experiments demonstrate that this approach significantly reduces false positive rates.