Intrusion Detection and Prevention System for Early Detection and Mitigation of DDoS Attacks in SDN Environment

Pulkit Ohri, Daniel Arockiam, Subhrendu Guha Neogi, Sunil Kumar Muttoo · 2024

Software Defined Networking (SDN) introduced the third layer, known as the control layer, due to which management and updating of devices became easy. The control layer in SDN provides an additional remote controlling feature of devices, which offers better management over traditional hardware networks. Traditional networking uses a hardwired mechanism for controlling the apparatus, a slow and complicated management approach. Unlike conventional networks, where every device needs to be updated separately, the SDN Control layer handles all the devices simultaneously. Only one command from the control layer can change, update, and manage hundreds of devices simultaneously. ONOS is the most popular and widely used Open Source SDN controller. So far, efforts have been made to improve the performance and availability of the ONOS controller. ONOS provides better performance and fault tolerance than any other controller available. However, no security module in the ONOS Controller can protect itself from DDoS attacks. This paper used the popular Suricata Intrusion Prevention System (IPS) to mitigate these web-based attacks. Wireshark statistics showed that our experimental study removed malicious DDoS traffic sent toward the control layer. This is the first study where Suricata actively detects and mitigates DDoS traffic sent toward the ONOS Controller.

Read the paper · More papers on PaperTik