Netinfo Security ›› 2022, Vol. 22 ›› Issue (1): 1-8.doi: 10.3969/j.issn.1671-1122.2022.01.001

Previous Articles     Next Articles

A Two-stage DDoS Attack Detection and Defense Method in Software Defined Network

YU Junqing1,2, LI Zizun1, WU Chi1, ZHAO Yizhu1()   

  1. 1. School of Cyber Science and Engineering, Huazhong University of Science and Technology, Wuhan 430074, China
    2. Center of Network and Computation, Huazhong University of Science and Technology, Wuhan 430074, China
  • Received:2021-09-13 Online:2022-01-10 Published:2022-02-16
  • Contact: ZHAO Yizhu E-mail:missbamboofirst@163.com

Abstract:

Distributed denial of service (DDoS) attacks have always been a major threat to Internet. In SDN network, it will lead to the exhaustion of controller resources and affect the normal operation of the entire network. Aiming at mitigating DDoS attacks in SDN network, a two-stage attack detection and defense method is designed and implemented, which firstly collects flow data based on the controller's northbound interface to extract direct and derived features, and uses sequential probability ratio test (SPRT) and light gradient boosting machine (LightGBM) to locate attacks quickly and differentiate attack types accurately, at last filters the attack traffic in real time by installing flow rules. Experimental results show that this attack detection method can quickly locate the attack port and classify the attack traffic which accuracy reaches to 98%, and attack defense method can install defense flow rules in time to filter the attack traffic within 2 s after attack happens to protect the safety of SDN network effectively.

Key words: software defined network, distributed denial of service attack, sequential probability ratio test, light gradient boosting machine

CLC Number: