Analysis Of Intrusion Prevention System (IPS) On Software Defined Network (SDN) In Preventing Distributed Denial of Service (DDoS) Attacks

Weny Irma Syafril, Bongga Arifwidodo, Dadiek Pranindito · 2024

The main concept of Software Defined Network is the centralization of network control in the Control Plane. However, the concept of a centralized network certainly needs to improve in terms of network security. The tendency to get attacks will be greater, such as Distributed Denial of Service (DDoS). By using the Intrusion Prevention System (IPS) can detect and block attacks. Snort functions as an attack detector, and the Ryu Controller acts as a firewall to block attacks. This study aims to collect QoS throughput data, CPU Usage, and Memory Usage under two conditions. The attack is carried out without IPS with packages that are gradually increased from 10, 100, 1000, and 10000 packets/s and when an attack is carried out with IPS integration on each attack package. The results TCP throughput value was obtained at 7.80 Gbps, and UDP was 778 MBps in normal conditions. The Throughput value began to decrease when an attack was carried out and decreased further when the attack packet was increased to 10000, which was 3.60 GBps for TCP and 338 MBps for UDP. During the DDoS attack by integrating IPS, the throughput was 3.92 GBps for TCP and 373 MBps for UDP. Also, CPU performance decreased when IPS was integrated by 34.6% for TCP and 13.9% for UDP. On the other hand, memory usage increased when 1402.8 MiB integrated IPS for TCP and 1541.8 MiB for UDP. This increase was due to the increasing number of system tasks in blocking attacks.

Read the paper · More papers on PaperTik