TCPFlood Defender
K. Muthamil Sudar, P. Nagaraj · 2024
The SDN is effective in a networking environment that is optimized and automated for dynamic changes, which promotes quick innovation in production and development. By combining the centralized controller and data plane switches into a single, unified platform, the SDN addresses issues in traditional networks. A weakened control plane bandwidth, a stressed-out SDN controller, and a switch that floods TCAM memory are all issues brought on by DDoS attacks in the SDN. As far as DDoS attacks are concerned, the TCP flood is a widespread attack on the SDN. To stimulate TCP SYN flooding attacks, an attacker drives the server to create a large number of half-open connections that overload the server queue and prevent authentic users from accessing the TCP connection with the server. The main objective of this work intends to put in place a defending mechanism against SDN TCP flooding attacks using statistical and ensemble machine learning-based mechanisms.