Fast DDoS Traffic Throttling and Normal Traffic Permitting in SDN-IoT: A Deep Reinforcement Learning Approach
Congqi Shen, Wanxin Gao, Qi Xu, Tao Zou, Jun Zhu, Ruyun Zhang · 2023
Recent Internet of Things (IoT) security incidents indicate that current IoT defense methods are insufficient to defend against DDoS attacks due to a lack of timely and plausible mitigation mechanisms. These methods may make wrong decisions on traffic throttling when network traffic patterns dynamically change. To swiftly and properly defend against DDoS attacks in IoT, we propose a novel deep reinforcement learning (DRL) based DDoS defense approach. Our goals are to both safeguard normal traffic and discard malicious traffic. To achieve these goals, we establish a software defined networking (SDN) based IoT network by replacing traditional IoT gateways at certain locations with SDN switches. The proposed method consists of network monitoring, reward evaluation, and defense policy execution. The DRL agent is able to monitor the whole network by utilizing various traffic features from the SDN-enabled IoT network framework. We propose an adaptive punishment based reward function to accelerate the learning procedure. We also propose an available bandwidth allocation algorithm to refine defense policy so as to protect more normal traffic. The experimental results demonstrate that the proposed method could determine optimal defense policy faster by around 200 episodes and forward more normal traffic by around 22%.