iCuSMAT-DT: A Two-Tier Detection Mechanism for High-Rate DDoS Attacks and Discriminating Benign Flash Traffic in Software-Defined Networks

Anam Rajper, Norlina Binti Paraman, Muhammad Nadzir Marsono, Noor Jahan Rajper · 2024

In the dynamic realm of Software-Defined Networks (SDN), the menace of Distributed Denial of Service (DDoS) attacks remains a pressing concern. This paper introduces iCuSMAT-DT, an enhanced two-tier DDoS detection mechanism tailored to alleviate controller overhead and accelerate detection accuracy. The nomenclature iCuSMAT -DT combines the inherent strengths of the non-parametric Cumulative sum (CUSUM) algorithm with sliding window (S), multidimensionality (M), adaptive threshold (AT) and harmonized with a Decision Tree (DT) classifier. A notable distinction of iCuSMAT -DT is its adeptness in discriminating between flash events and DDoS traffic, an initial shortcoming where flash traffic could be erroneously detected as DDoS. This is surmounted by integrating a second-tier DT classifier, which refines the process by distinguishing between legitimate flash traffic and genuine DDoS threats. Consequently, iCuSMAT-DT not only diminishes the burden on the controller but also secures accuracy and minimizes detection time. The experimental evaluation of the proposed two-tier detection method is performed using both on-line traffic and benchmark SDN-specific DDoS datasets, IEEE Dataport and Mendeley. The results demonstrate that iCuSMAT -DT transcends the performance of a standalone DT, exhibiting superior detection precision and markedly reduced latency, particularly in real-time traffic conditions. Furthermore, comparative analyses with existing detection frameworks affirm the enhanced proficiency of iCuSMAT-DT in terms of detection speed, accuracy, and controller computational overhead. The encouraging empirical evidence solidifies the potential of iCuSMAT -DT as an effective and scalable countermeasure for DDoS attacks in SDN environment, thus contributing to a more robust network infrastructure. Through iCuSMAT-DT, this work motivates the discourse towards integrating statistical and machine learning approaches to fortify network security, marking a substantial advancement in the ongoing battle against DDoS attacks within the security landscape of SDN.

Read the paper · More papers on PaperTik