Return
Multi-Layer Traffic Analysis Framework for DDoS Attacks in Software-Defined IoT Networks
DOI:10.3390/fi18030164.png)
Abstract
En 中文
The data plane and the control plane are targets for Distributed Denial of Service (DDoS) attacks in the Software-Defined Internet of Things (SDIoT). Currently available studies rely on observations from a single network layer which limits the cross-layer attack analysis. This paper presents a synchronized, phase-aware, and a multi-layer traffic collection framework mimicking SDIoT environments under diverse DDoS attack scenarios. The data collected are the metrics captured at host, switch, and controller layers during normal, attack, and post-attack phases with strict temporal alignment. For capturing diverse DDoS attack behaviors in SDIoT environments, representative data plane attacks including volumetric flooding and switch-level flow table saturation were used. Control plane level attack targeting the SDN controller was implemented. The evaluation was done using a Mininet-based SDIoT testbed with a POX controller. Each scenario is executed across five independent runs with statistical validation. The proposed framework enables reproducible and time-aligned multi-layer analysis through standardized orchestration and automated logging. Results indicate that SDIoT DDoS behavior demonstrates differently across traffic, state, and resource-level metrics, and that accurate characterization benefits from temporally aligned multi-layer monitoring rather than relying solely on packet rate analysis.
Keywords:
SDIoT
DDoS attacks
multi-layer traffic collection
control plane attacks
data plane attacks
AI Summary
Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.
Journal
IF:
3.6
Papers:
1.2K
Citations:
6.5K

