Mitigation of DDoS Attacks in SDN using Access Control List, Entropy and Puzzle-based Mechanisms
Amit Ladigatti, Vinayak Merawade, Shashvi Jain, Anagha A. Bengeri, D. G. Narayan, Pooja Shettar · 2023
Software Defined Networking (SDN) has become increasingly popular as a networking paradigm due to its advantages over traditional networks, such as scalability, flexibility, and programmability. However, SDN networks face security threats, particularly from Distributed Denial of Service (DDoS) attacks. These attacks aim to overwhelm a target server or network by flooding it with illegitimate traffic, rendering it inaccessible to legitimate users. Currently, most DDoS attack detection methods rely on supervised learning models. In this study, we propose an alternative approach using unsupervised learning. specifically combining fusion entropy and computational puzzles. Our proposed method involves three steps. Firstly, access control lists are implemented for IP filtering to reduce the attack load on the controller. Secondly, we utilize the fusion entropy method to detect DDOS attacks and identify potentially suspicious hosts. Lastly, we employ a Proof of Work based computational puzzle on these suspicious hosts to detect and mitigate the attacks. The proposed work is implemented in Mininet emulator with POX as controller. The results demonstrate that this mitigation technique enhances accuracy by reducing the occurrence of false positives.