SDN Defense: Detection and mitigation of DDoS attack via IoT Network

K Rajkumar, S. Mercy Shalinie, Hamil Stanly · 2024

Internet-of-things is one of the prominent communication technologies in the 21st century. We can connect everyday objects, like baby monitors, thermostats, e-health, etc., Connecting IoT with Software-defined networking is the best approach to security provisioning during network communication. Because the enormous features of SDN are programmable and centralized management, attackers can create multiple security vulnerabilities in SDN that redeem the distributed denial-of-service attack. This security breach causes bandwidth depletion and server resource impoverishment and perplexes benign users. This study proposes and builds a DDoS attack detection and mitigation defense system for SDN to address this issue. Two different defense modules are deployed in the SDN controller: suspicious identification, and mitigation of the malicious traffic flow. The first module of the SDN defense system used for detecting malignant traffic from DDoS attacks which works under a CNN-ELM is an integrated deep learning approach that combines a convolutional neural network with an extreme learning machine. The suspicious flows are identified, whether benign or malignant, by using a hybrid CCN-ELM model, and this process improves the accuracy of the attack detection. The second module of the mitigation strategy identifies the attacker's location by using IP traceback and removes that malicious traffic by transmitting the flow rule from the controller. These two SDN defense modules are evaluated by simulation processes. Finally, the experimental results of the SDN defense system, precisely detect the DDoS attack with an accuracy of 99.85% and efficiently mitigate the malicious traffic flow in real-time.

Read the paper · More papers on PaperTik