An Intelligent Software Defined Networking Controller Component to Detect and Mitigate Denial of Service Attacks
DOI:
https://doi.org/10.32890/jict2021.20.1.4Keywords:
Security, DoS attack, decision making, software defined networking, POX controllerAbstract
Despite many advantages of software defined networking (SDN) such as manageability, scalability, and performance, it has inherent security threats. In particular, denial of service (DoS) attacks are major threats to SDN. The controller’s processing and communication abilities are overwhelmed by DoS attacks. The capacity of the flow tables in the switching device is exhausted due to excess flows created by the controller because of malicious packets. DoS attacks on the controller cause the network performance to drop to a critical level. In this paper, a new SDN controller component was proposed to detect and mitigate DoS attacks in the SDN controller. POX layer three controller component was used for underlying a testbed for PacketIn messages. Any packet from the host was incremented to measure the rate of packet according to its device identification and its input port number. Considering the rate of packets received by the controller and threshold set, malicious packets could be detected and mitigated easily. A developed controller component was tested in a Mininet simulation environment with an hping3 tool to build artificial DoS attacks. Using the enhanced controller component, DoS packets were prevented from accessing the controller and thus, the data plane (switching devices) was prevented from being filled with unwanted flows.
References
Ali, S. T., Sivaraman, V., Radford, A., & Jha, S. (2015). A survey of securing networks using software defined networking. IEEE transactions on reliability, 64(3), 1086–1097. https://doi.org/10.1109/TR.2015.2421391
Benton, K., Camp, L. J., & Small, C. (2013). OpenFlow vulnerability assessment. In Proceedings of the second ACM SIGCOMM workshop on Hot topics in software defined networking (pp. 151–152). Hong Kong, China: ACM. https://doi.org/10.1145/2491185.2491222
Bholebawa, I. Z., & Dalal, U. D. (2016). Design and performance analysis of OpenFlow-enabled network topologies using Mininet. International Journal of Computer and Communication Engineering, 5(6), 419. https://doi.org/10.17706/IJCCE.2016.5.6.419-429
Cabaj, K., Wytrebowicz, J., Kuklinski, S., Radziszewski, P., & Dinh, K. T. (2014). SDN architecture impact on network security. In M. Ganzha, L. Maciaszek, M. Paprzycki (Eds.), Federated Conference on Computer Science and Information Systems (FedCSIS) (pp. 143–148). Warsaw, Poland: ACSIS. https://doi.org/10.15439/2014F473
Cui, Y., Yan, L., Li, S., Xing, H., Pan, W., Zhu, J., & Zheng, X. (2016). SD-Anti-DDoS: Fast and efficient DDoS defense in software-defined networks. Journal of Network and Computer Applications, 68, 65–79. https://doi.org/10.1016/j.jnca.2016.04.005
Dao, N.-N., Kim, J., Park, M., & Cho, S. (2016). Adaptive suspicious prevention for defending DoS attacks in SDN-based convergent networks. PloS one, 11(8), e0160375. https://doi.org/10.1371/journal.pone.0160375
Dridi, L., & Zhani, M. F. (2016). SDN-guard: DoS attacks mitigation in SDN networks. In 5th IEEE International Conference on Cloud Networking (Cloudnet) (pp. 212–217). Pisa, Italy: IEEE. https://doi.org/10.1109/ CloudNet.2016.9
Imran, M., Durad, M. H., Khan, F. A., & Derhab, A. (2019). Reducing the effects of DoS attacks in software defined networks using parallel flow installation. Human-centric Computing and Information Sciences, 9(1), 16. https://doi.org/10.1186/s13673-019-0176-7
Kim, H., & Feamster, N. (2013). Improving network management with software defined networking. IEEE Communications Magazine, 51(2), 114–119. https://doi.org/10.1109/MCOM.2013.6461195
Kreutz, D., Ramos, F., & Verissimo, P. (2013). Towards secure and dependable software-defined networks. In Proceedings of the Second ACM SIGCOMM Workshop on Hot Topics in Software Defined Networking (pp. 55–60). Hong Kong, China: ACM. https://doi.org/10.1145/2491185.2491199
Kreutz, D., Ramos, F. M., Verissimo, P., Rothenberg, C. E., Azodolmolky, S., & Uhlig, S. (2015). Software-defined networking: A comprehensive Journal of ICT, 20, No. 1 (January) 2021, pp: 57-survey. Proceedings of the IEEE, 103(1), 14–76. https://doi.org/10.1109/ JPROC.2014.2371999
Lawal, B. H., & Nuray, A. T. (2018). Real-time detection and mitigation of distributed denial of service (DDoS) attacks in software defined networking (SDN). In 26th Signal Processing and Communications Applications Conference (SIU) (pp. 1–4). Izmir, Turkey: IEEE. https://doi.org/10.1109/SIU.2018.8404674
Li, W., Meng, W., & Kwok, L. F. (2016). A survey on OpenFlow-based software defined networks: Security challenges and countermeasures. Journal of Network and Computer Applications, 68, 126–139. https://doi.org/10.1016/j.jnca.2016.04.011
Maugendre, M. (2015). Development of a performance measurement tool for SDN. (Unpublished Master’s thesis). Universitat Politècnica de Catalunya, Spain.
Padmaja, S., & Vetriselvi, V. (2016). Mitigation of switch-Dos in software defined network. In International Conference on Information Communication and Embedded Systems (ICICES) (pp. 1–5). Chennai, India: IEEE. https://doi.org/10.1109/ICICES.2016.7518925
Polat, H., Polat, O., Cetin, A. (2020). Detecting DDoS Attacks in Software-Defined Networks Through Feature Selection Methods and Machine Learning Models. Sustainability, 12(3),1035. https://doi.org/10.3390/ su12031035
Proença, J., Cruz, T., Monteiro, E., & Simões, P. (2015). How to use software-defined networking to improve security - A survey. In Proceedings of the 14th European Conference on Cyber Warfare and Security. Hertfordshire, UK. https://doi.org/10.13140/RG.2.1.4877.1686
Scott-Hayward, S., O’Callaghan, G., & Sezer, S. (2013). SDN security: A survey. In IEEE SDN For Future Networks and Services (SDN4FNS) (pp. 1–7). Trento, Italy: IEEE. https://doi.org/10.1109/SDN4FNS.2013.6702553
Sen, S., Gupta, K. D., & Ahsan, M. M. (2020). Leveraging machine learning approach to setup software-defined network (SDN) controller rules during DDoS attack. In Proceedings of International Joint Conference on Computational Intelligence (pp. 49–60). Singapore: Springer. https://doi.org/10.1007/978-981-13-7564-4_5
Shang, G., Zhe, P., Bin, X., Aiqun, H., & Kui, R. (2017). FloodDefender: Protecting data and control plane resources under SDN-aimed DoS attacks. In IEEE INFOCOM 2017 - IEEE Conference on Computer Communications (pp. 1–9). Atlanta, GA, USA: IEEE: https://doi.org/10.1109/INFOCOM.2017.8057009
Shin, S., Yegneswaran, V., Porras, P., & Gu, G. (2013). Avant-guard: Scalable and vigilant switch flow management in software-defined networks. In Proceedings of the 2013 ACM SIGSAC Conference on Computer Journal of ICT, 20, No. 1 (January) 2021, pp: 57- & Communications Security (pp. 413–424). Berlin, Germany: ACM. https://doi.org/10.1145/2508859.2516684
Shu, Z., Wan, J., Li, D., Lin, J., Vasilakos, A. V., & Imran, M. (2016). Security in software-defined networking: Threats and countermeasures. Mobile Networks and Applications, 21(5), 764–776. https://doi.org/10.1007/ s11036-016-0676-x
Stancu, A., Halunga, S., Suciu, G., & Vulpe, A. (2015). An overview study of software defined networking. In Proceedings of the 14th International Conference of Informatics in Economy. Bucharest, Romania.
Tian, Y., Tran, V., & Kuerban, M. (2019). DoS attack mitigation strategies on SDN controller. In IEEE 9th Annual Computing and Communication Workshop and Conference (CCWC) (pp. 0701–0707). Las Vegas, NV, USA: IEEE. https://doi.org/10.1109/CCWC.2019.8666456
Tran, N. T., Le, T. L., & Tran, M. A. T. (2018). ODL-ANTIFLOOD: A comprehensive solution for securing OpenDayLight controller. In International Conference on Advanced Computing and Applications (ACOMP) (pp. 14–21). Ho Chi Minh City, Vietnam: IEEE. https://doi.org/10.1109/ACOMP.2018.00011
Wang, H., Xu, L., & Gu, G. (2015). Floodguard: A DoS attack prevention extension in software-defined networks. In 45th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (pp. 239–250). Rio de Janeiro: IEEE. https://doi.org/10.1109/DSN.2015.27
Wright, A. P., & Ghani, N. (2019). A testbed for the evaluation of denial of service attacks in software-defined networks. In 2019 SoutheastCon (pp. 1–6). Huntsville, AL, USA: IEEE. https://doi.org/10.1109/ SoutheastCon42311.2019.9020433
Xia, W., Wen, Y., Foh, C. H., Niyato, D., & Xie, H. (2015). A survey on software-defined networking. IEEE Communications Surveys & Tutorials, 17(1), 27–51. https://doi.org/10.1109/COMST.2014.2330903
Xie, J., Guo, D., Hu, Z., Qu, T., & Lv, P. (2015). Control plane of software defined networks: A survey. Computer Communications, 67, 1–10. https://doi.org/10.1016/j.comcom.2015.06.004
Zhang, P., Wang, H., Hu, C., & Lin, C. (2016). On denial of service attacks in software defined networks. IEEE Network, 30(6), 28–33. https://doi.org/10.1109/MNET.2016.1600109NM
Published
Issue
Section
How to Cite
Research impact
Harvested 2026-09-06Counts differ between services because each indexes a different body of literature. None of them is the whole picture.
2002 - 2020






















