Flood control: Tcp-syn flood detection for software-defined networks using openflow port statistics

T Das, OA Hamdan, S Sengupta… - 2022 IEEE International …, 2022 - ieeexplore.ieee.org
2022 IEEE International Conference on Cyber Security and …, 2022ieeexplore.ieee.org
As software-defined network (SDN) adoption increases, it becomes increasingly important to
develop effective solutions to defend them against cyber attacks. A prominent cyberattack
that can compromise SDNs is TCP-SYN floods, which can exhaust network resources by
initiating too many fraudulent TCP connections. Previous efforts to detect SYN Flood attacks
mainly rely on statistical methods to process mirrored traffic or flow statistics. Thus, they
either incur high overhead (in the case of port mirroring) or lead to low accuracy (in the case …
As software-defined network (SDN) adoption increases, it becomes increasingly important to develop effective solutions to defend them against cyber attacks. A prominent cyberattack that can compromise SDNs is TCP-SYN floods, which can exhaust network resources by initiating too many fraudulent TCP connections. Previous efforts to detect SYN Flood attacks mainly rely on statistical methods to process mirrored traffic or flow statistics. Thus, they either incur high overhead (in the case of port mirroring) or lead to low accuracy (in the case of using flow statistics). In this paper, we propose a machine learning (ML)-enabled TCP-SYN flood detection framework using Openflow port statistics. We demonstrate that ML models such as Random Forest classifiers can differentiate normal traffic from SYN flood traffic with up to 98% accuracy. We also introduce a novel threat localization technique that can pinpoint where the attack traffic originates from in the network.
ieeexplore.ieee.org
以上显示的是最相近的搜索结果。 查看全部搜索结果