Sequential Heuristic Model for DDOS Attack Detection in Software-Defined Network
Tooba Shaikh · 2023
Software Defined Networking (SDN) is a new networking paradigm that uses a central controller to streamline network administration while increasing flexibility and evolution. Because of its centralized management and programmable nature, SDN is susceptible to distributed denial of service (DDoS) attacks which can exploit security weaknesses. These attacks can overload the switch and controller's memory, drain server resources and network bandwidth, disrupting normal user access. This research proposes an anomaly detection technique employing higher-order statistics, such as skewness and kurtosis, to detect DOS and DDoS attacks, specifically focusing on TCP Flood and UDP Flood in an SDN environment. This algorithm efficiently recognizes when an attack occurred and determines the exact moment it occurred. We examined the performance of our algorithm using a dataset transmitted between hosts in an SDN environment, testing it with various window sizes. Through a comparative analysis, we demonstrated the superior capability of our proposed methodology in detecting malicious flows within SDN-based networks. To assess performance, we employed detection rate and FPR (False Positive Rate) as evaluation parameters and validated the effectiveness of our approach utilizing a configuration employed within the Mininet network emulator.