Flooding DDoS mitigation and traffic management with software defined networking

A Kalliola, K Lee, H Lee, T Aura - 2015 IEEE 4th International …, 2015 - ieeexplore.ieee.org
A Kalliola, K Lee, H Lee, T Aura
2015 IEEE 4th International Conference on Cloud Networking (CloudNet), 2015ieeexplore.ieee.org
Mitigating distributed denial-of-service attacks can be a complex task due to the wide range
of attack types, attacker adaptation, and defender constraints. We propose a defense
mechanism which is largely automated and can be implemented on current software defined
networking (SDN)-enabled networks. Our mechanism combines normal traffic learning,
external blacklist information, and elastic capacity invocation in order to provide effective
load control, filtering and service elasticity during an attack. We implement the mechanism …
Mitigating distributed denial-of-service attacks can be a complex task due to the wide range of attack types, attacker adaptation, and defender constraints. We propose a defense mechanism which is largely automated and can be implemented on current software defined networking (SDN)-enabled networks. Our mechanism combines normal traffic learning, external blacklist information, and elastic capacity invocation in order to provide effective load control, filtering and service elasticity during an attack. We implement the mechanism and analyze its performance on a physical SDN testbed using a comprehensive set of real-life normal traffic traces and synthetic attack traces. The results indicate that the mechanism is effective in maintaining roughly 50% to 80% service levels even when hit by an overwhelming attack.
ieeexplore.ieee.org
Showing the best result for this search. See all results