2015 45th Annual IEEE/IFIP International Conference on Dependable Systems and Networks 2015
DOI: 10.1109/dsn.2015.27
|View full text |Cite
|
Sign up to set email alerts
|

FloodGuard: A DoS Attack Prevention Extension in Software-Defined Networks

Abstract: This paper addresses one serious SDN-specific attack, i.e., data-to-control plane saturation attack, which overloads the infrastructure of SDN networks. In this attack, an attacker can produce a large amount of table-miss packet_in messages to consume resources in both control plane and data plane. To mitigate this security threat, we introduce an efficient, lightweight and protocol-independent defense framework for SDN networks. Our solution, called FLOODGUARD, contains two new techniques/modules: proactive f… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
1
1

Citation Types

0
160
0
8

Year Published

2016
2016
2022
2022

Publication Types

Select...
5
4

Relationship

0
9

Authors

Journals

citations
Cited by 301 publications
(183 citation statements)
references
References 17 publications
0
160
0
8
Order By: Relevance
“…Avant-Guard [3] shows a new attack (which is called data-to-control plane saturation attack) against SDN networks and provide solutions to prevent such attacks. FloodGuard [7] provides a new solution to this attack. Besides, SPHINX [2] proposes a unified approach to use network graphs to detect attacks that violate those learned flow graphs.…”
Section: Security Research For Sdn Networkmentioning
confidence: 99%
“…Avant-Guard [3] shows a new attack (which is called data-to-control plane saturation attack) against SDN networks and provide solutions to prevent such attacks. FloodGuard [7] provides a new solution to this attack. Besides, SPHINX [2] proposes a unified approach to use network graphs to detect attacks that violate those learned flow graphs.…”
Section: Security Research For Sdn Networkmentioning
confidence: 99%
“…AvantGuard can alleviate TCP saturation attack effectively which however, has some limitation for other protocols. FloodGuard [11] is another approach which is also proposed to defend saturation attack in both control plane and data plane. FloodGuard adopts proactive flow rules to preserve network policy enforcement and packet migration mechanism to protect the controller from being overloaded.…”
Section: Related Workmentioning
confidence: 99%
“…end if (12) end for ( a product of innovations (errors) of the past terms and its standard deviation by = ,…”
Section: Forecastmentioning
confidence: 99%
“…AvantGuard [2] introduces connection migration and actuating triggers into the SDN architecture to defend against the SYN Flood attacks, but it does not work well when confronted with other DoS attacks in SDN. FloodGuard [12] uses proactive flow rule analyzer and packet migration to defend against data plane saturation attack, but it is too costly. Previously related works, such as [13,14], employed Self Organizing Maps (SOM) to classify whether the traffic is abnormal or not to defend against DoS attacks, but the overhead of the classification is also too high to be used in real time.…”
Section: Related Workmentioning
confidence: 99%