期刊论文详细信息
IEEE Access 卷:8
Detecting DoS Attacks Based on Multi-Features in SDN
Huaiyuan Wang1  Meng Yue1  Zhijun Wu1  Liang Liu1 
[1] School of Electronics, Information and Automation, Civil Aviation University of China, Tianjin, China;
关键词: SDN security;    DoS;    feature detection;    flow table;    flash crowd;   
DOI  :  10.1109/ACCESS.2020.2999668
来源: DOAJ
【 摘 要 】

Denial of Service (DoS) attack is a serious threat to Software Defined Network (SDN). Although many research efforts have been devoted to identify new features for DoS attack detection, the existing approaches are not able to detect various types of DoS attacks. In SDN, DoS attacks against data plane are mainly organized in two ways: 1) DoS attack with multiple flow entries (M-DoS) to exhaust the Ternary Content-Addressable Memory (TCAM) resource of the switch. 2) DoS attack with a single well-designed entry (S-DoS) to overwhelm the target link and further impact the controller. To detect these two attacks, we propose a new approach by extracting six features of flow table, and using the back propagation (BP) neural network to construct the classifier. Test results of test-bed experiments indicate that the accurate detection probability of proposed approach is 98.9%, which can effectively distinguish M-DoS flows and S-DoS flows without being affected by Flash crowd scene.

【 授权许可】

Unknown   

  文献评价指标  
  下载次数:0次 浏览次数:0次