AI Chat Paper
Note: Please note that the following content is generated by AMiner AI. SciOpen does not take any responsibility related to this content.
{{lang === 'zh_CN' ? '文章概述' : 'Summary'}}
{{lang === 'en_US' ? '中' : 'Eng'}}
Chat more with AI
Article Link
Collect
Submit Manuscript
Show Outline
Outline
Show full outline
Hide outline
Outline
Show full outline
Hide outline
Regular Paper

An Efficient Scheme to Defend Data-to-Control-Plane Saturation Attacks in Software-Defined Networking

School of Cyber Science and Technology, University of Science and Technology of China, Hefei 230027, China
College of Science and Engineering, Kanazawa University, Kanazawa 920-1192, Japan

A preliminary version of the paper was published in the Proceedings of MASS 2020.

Show Author Information

Abstract

Software-defined networking (SDN) decouples the data and control planes. However, attackers can lead catastrophic results to the whole network using manipulated flooding packets, called the data-to-control-plane saturation attacks. The existing methods, using centralized mitigation policies and ignoring the buffered attack flows, involve extra network entities and make benign traffic suffer from long network recovery delays. For these purposes, we propose LFSDM, a saturation attack detection and mitigation system, which solves these challenges by leveraging three new techniques: 1) using linear discriminant analysis (LDA) and extracting a novel feature called control channel occupation rate (CCOR) to detect the attacks, 2) adopting the distributed mitigation agents to reduce the number of involved network entities and, 3) cleaning up the buffered attack flows to enable fast recovery. Experiments show that our system can detect the attacks timely and accurately. More importantly, compared with the previous work, we save 81% of the network recovery delay under attacks ranging from 1, 000 to 4,000 packets per second (PPS) on average, and 87% of the network recovery delay under higher attack rates with PPS ranging from 5,000 to 30,000.

Electronic Supplementary Material

Download File(s)
1495_ESM.pdf (1.6 MB)

References

【1】
【1】
 
 
Journal of Computer Science and Technology
Pages 839-851

{{item.num}}

Comments on this article

Go to comment

< Back to all reports

Review Status: {{reviewData.commendedNum}} Commended , {{reviewData.revisionRequiredNum}} Revision Required , {{reviewData.notCommendedNum}} Not Commended Under Peer Review

Review Comment

Close
Close
Cite this article:
Huang X-B, Xue K-P, Xing Y-T, et al. An Efficient Scheme to Defend Data-to-Control-Plane Saturation Attacks in Software-Defined Networking. Journal of Computer Science and Technology, 2022, 37(4): 839-851. https://doi.org/10.1007/s11390-022-1495-0

729

Views

6

Crossref

6

Web of Science

6

Scopus

0

CSCD

Received: 04 April 2021
Revised: 06 April 2022
Accepted: 24 May 2022
Published: 25 July 2022
©Institute of Computing Technology, Chinese Academy of Sciences 2022