Link Flooding Attack Mitigation Method Based on SDN Service Priority
Jiancheng Wang, Jinlong Fei, Yuefei Zhu, Xuemeng Wang, Xiangnan Lin · 2025
As a new type of DDoS attack, the link flooding attack (LFA) aims to paralyze the critical links of the network to isolate the target area. LFA has the characteristics that the traffic similarity between a single attacking host and legitimate hosts is high, and its bandwidth occupation ratio is small, which makes detection difficult. However, the existing methods still rely on the traditional DDoS detection features, and these methods are hardly applicable when detecting LFA. To effectively defend against LFA, we propose a service-priority-based link flooding attack detection and mitigation method (SPM) on the software defined network (SDN). The SPM method focuses on specific target services and monitors the critical links by constructing the mapping relationship between services and links. By deeply analyzing the characteristics of LFA attack behaviors, it extracts the host behavior features from the flow table information of switches during the congestion period and uses machine learning models to judge the features. For the detected malicious hosts, SPM adopts a defense strategy of quick mitigation and slow detection to reduce the impact on legitimate hosts. Based on the experimental results of the simulation platform, in different attack environments, compared with the comparison methods, the SPM method can quickly identify malicious hosts. Moreover, the detection rate of malicious hosts by the SPM method reaches more than 90%, and the false positive rate is lower than 1.5%.