ML based Detection and Mitigation Scheme for DoS attacks on SDN Controllers

Tamer R. Omar, Barret Griffin, Jose Garcia · 2023

The development and use of Software-Defined Networks (SDN) has been a way to improve upon traditional networking. Traditional networks entirely depend on fixed and dedicated hardware to control network traffic. SDNs enable network control and management through software-based applications. An integral part of SDNs is the network controller, a centralized application responsible for creating traffic flows between all network devices. Though they are valuable and integral to the function of SDNs, controllers are also susceptible to attacks and can be exploited as a single point of failure in the entire network. This study investigates the detection and mitigation of Denial of Service (DoS) attacks on a Ryu controller, by setting a traffic baseline, detecting the attack using TensorFlow machine learning platform, and blocking the attacker’s by utilizing native iptables feature in the SDN controller. This study aims at testing the capability and reliability of machine learning to detect DoS attacks. Traditional programming methods for cyber security involve manually creating rules to detect attacks based on irregular data transferred by the TCP/IP Protocol stack. TensorFlow eliminates the need to create rules based the defense strategies on data sets training and neural networks. The results of this study shows the capability of the proposed machine learning algorithm to effectively detect the DoS and the southbound adopted mitigation methodology was capable of blocking the attacker traffic and control the inbound flows to the SDN controller.

Read the paper · More papers on PaperTik