Enhanced DDoS Defense in SDN: Double-Layered Strategy with Blockchain Integration
Jialin Tian, Zhaogang Shu, Shuwu Chen, Haihui Xie, Xiaolong Liu, Caiyu Qiu · 2024
With the development of technologies such as cloud computing, big data, and the Internet of Things (IoT), Software-Defined Networking (SDN) has emerged as a novel network architecture in today's Internet era. It can separate the control plane from the data plane, allowing rapid packet forwarding in the Internet through a centralized controller. However, SDN environments are vulnerable to traditional Distributed Denial of Service (DDoS) attacks. This paper proposes a new dual layer strategy to try to mitigate the question. First, by using blockchain technology and smart contract in the northbound interface to store the flow tables required for SDN networks, security is increased. Then, we use the Token Bucket algorithm and Time Window algorithm to build the first-tier strategy to defend against obvious DDoS attacks. To detect unobvious DDoS attacks, we design the second-tier strategy that uses a composite data feature correlation coefficient calculation method and the Isolation Forest algorithm to perform binary classification on data, thereby identifying abnormal traffic. We use the currently publicly available DDoS dataset CIC-DDoS2019 for experimental verification. The results show that using this strategy in SDN networks results in an average deviation of data Round-Rip Time (RTT) approximately 38.86% lower than in the original SDN networks without this strategy. Additionally, the accuracy of DDoS attack identification reaches 91.29%. This means that with the implementation of this strategy, DDoS attacks can be effectively identified without compromising the stability of data transmission in SDN network environments.