DDoSBlocker: A Protocol-Independent and Lightweight Defense Mechanism against Multi-Layer DDoS Attacks in SDN

Mitali Sinha, Padmalochan Bera, Manoranjan Satpathy · Distributed Ledger Technologies Research and Practice · 2025

Software-Defined Networking (SDN) leverages centralized control to enhance network flexibility, programmability, and resource management. However, this centralization also makes it susceptible to Distributed Denial of Service (DDoS) attacks. In this attack, both compromised hosts and malicious third-party applications flood the controller with fake requests, causing network disruptions and potential failures. Existing literature lacks a comprehensive solution that effectively addresses both compromised host-based and application-layer DDoS attacks. Additionally, there is no mitigation mechanism capable of blocking malicious traffic directly at its source. To address this limitation, we propose DDoSBlocker which is a protocol-independent and lightweight DDoS defense mechanism against multi-layer DDoS attacks in SDN. It consists of three essential modules. The first module identifies the source points of compromised hosts responsible for DDoS attacks by leveraging time-based mapping technique integrated with machine learning technique. The second module detects malicious third-party applications by analyzing their application IDs using a machine learning approach with six novel features. Finally, the last module implements a mitigation strategy that effectively blocks malicious traffic at its source, ensuring minimal impact on legitimate network operations. DDoSBlocker is deployed in the Floodlight controller, and its effectiveness is assessed across multiple network scenarios. Our experimental results demonstrate that DDoSBlocker successfully detects and mitigates various types of DDoS attacks while achieving a 25–53% reduction in False Positive Rate (FPR) compared to existing approaches.

Read the paper · More papers on PaperTik