arrow
Return

A multi-layered intrusion detection system for software defined networking

delete2022-07-01
delete7
PRE
AI
H
Hamideh Bour *
M
Mehran Abolhasan
S
Saber Jafarizadeh
J
Justin Lipman
I
Imran Makhdoom
DOI:10.1016/j.compeleceng.2022.108042delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
The majority of existing DDoS defense mechanisms in SDN impose a significant computational burden on the controller and employ limited flow statistics and packet features. Tackling these issues, this paper presents a multi-layer defense mechanism that detects and mitigates three distinct types of flooding DDoS attacks. In the proposed framework, the detection process consists of flow-based and packet-based attack detection mechanisms employing Extreme Learning Machine-based Single-hidden Layer Feedforward Networks (ELM-SLFNs) and Case-based Information Entropy (C-IE), respectively. Moreover, the affected switches are avoided in the optimal path determined by the Floyd-Warshall algorithm, where the switches are classified based on the Hidden Markov Model (HMM) using the extracted packet features. Our simulation demonstrates the improved performance of our framework compared to similar schemes proposed in the literature in terms of different metrics, including attack detection rate, detection accuracy, false positive rate, switch failure ratio, packet loss rate, response time, and CPU utilization.
Keywords:
DDoS attack detection and mitigation
Software-defined networking
Extreme learning machine-based feed-forward
networks
Case-based information entropy
Hidden Markov model

Journal

C
Computers and Electrical Engineering
IF:
4.9
Papers:
6.7K
Citations:
1.3W

Organization

R
rakuten group, inc
Scholars:
28
Papers: 34
Citations: 0
U
university of technology sydney
Scholars:
1.6W
Papers: 2.0W
Citations: 25