An Entropy-Based Methodology for Detecting and Mitigating DDoS Attacks in SDN Environments to Improve Control Plane Security

Loading...
Thumbnail Image

Journal Title

Journal ISSN

Volume Title

Publisher

ASTU

Abstract

As we all know, the architectural framework of software-defined networking (SDN) reduces network managers' work by separating the data plane from the control plane. This makes network deployment easier by providing a programmable interface for application development in areas such as security management, and the centralized logical controller provides greater control over the entire network, which has complete network visibility. This study was done to design a mechanism for implementing a security solution for detecting and mitigating distributed denial of service (DDoS) on the SDN control plane. The proposed approach will be based on an early detection strategy that is aligned with the standard and used by professionals in the field as a guide for implementing such security solutions. This thesis describes an approach that was used to identify and mitigate the risks associated with the OpenFlow protocol and its POX controller. The methodology is validated by performing activities in a controlled simulation scenario using the Mininet tool and the SDN controller. The detection algorithm's results were observed through simulation, then implemented into a network testbed, and the proposed algorithm's results are presented and analyzed. As a result of the methodology's successful use, the problem has been solved by implementing a DDoS attack detection mechanism based on the network's entropy calculation and mitigation by blocking the switch port from which the malicious traffic is generated. The solution is quick and effective against various types of DDoS attacks, including TCP, UDP, and ICMP floods

Description

Citation

Endorsement

Review

Supplemented By

Referenced By