Evaluating DDoS Detection and Mitigation in SDN at Various Attack Rates

Naziya Aslam, Shashank Srivastava, Manoj Madhava Gore · 2024

Software-Defined Networking (SDN) surpasses traditional network systems in terms of programmability, management, flexibility, and efficiency due to its distinct separation of data and control planes. The central management of devices is crucial in handling Distributed Denial of Service (DDoS) attacks, providing a comprehensive view of the network and the capability to analyze network traffic to detect malicious activity. Despite the advantages of separation of control and data planes, this architecture is susceptible to DDoS attacks, which pose challenges in real-time detection and resistance. Effective countermeasures against such attacks rely on carefully selecting features for attack detection. Our work focuses on detecting DDoS attack using ensemble Machine Learning (ML) techniques. Mitigation is done by trace backing approach to locate the source of attack. A thorough result analysis is done based on attack rate, detection time and mitigation time to test the ONOS Flood Defender Application for detection and mitigation of DDoS attack.

Read the paper · More papers on PaperTik