DDoS Flood Detection and Mitigation using SDN and Network Ingress Filtering - an Experiment Report
Sebastien Marleau, P. Abdul Rahman, Chung–Horng Lung · 2024
Distributed Denial of Service (DDoS) attacks are a common security threat to overwhelm a target server. IP source spoofing is a common approach used for DDoS attacks. It is claimed that all large DDoS attacks require IP spoofing and around 20% of the Internet still allows IP spoofing. DDoS attacks can also be launched much more easily using low-cost Internet of Things (IoT) devices. DDoS attacks originating from IoT devices have increased 5-fold in a year. Software-defined networking (SDN) has been proposed as a new paradigm to reduce complexity. However, security issues are still challenging for SDN, as DDoS attacks on the controller could fail the entire network. A mechanism that can detect and mitigate DDoS attacks on SDN is crucial. Ingress filtering has been adopted to reduce the probability of exploiting a network to launch an attack. This, among other things, mandates the dropping of packets if the source IP address of incoming packets is inconsistent with the configured one. Best Current Practice 38 (BCP 38) is a network ingress filtering technique to prevent source IP spoofing. By validating incoming packets, their IP addresses, and possibly other attributes at the ingress devices, it provides a first line of defense against suspicious traffic. We present an approach to DDoS detection and mitigation using BCP 38 and SDN. To evaluate the effectiveness of the proposed approach, a simple method was designed to detect and mitigate DDoS floods using BCP 38 and SDN. Experiments were conducted using Mininet and the Ryu controller. The result demonstrated that the proposed approach corresponded to DDoS attacks with IP spoofing efficiently and effectively.