Skip to main content

2020 | OriginalPaper | Buchkapitel

Detecting Denial-of-Service Attacks Using sFlow

verfasst von : Shivaraj Hublikar, Vijaya Eligar, Arun Kakhandki

Erschienen in: Inventive Communication and Computational Technologies

Verlag: Springer Singapore

Aktivieren Sie unsere intelligente Suche, um passende Fachinhalte oder Patente zu finden.

search-config
loading …

Abstract

This paper addresses how to detect denial-of-service attacks using sFlow. Denial-of-service (DoS) attack is a critical security challenge in software-defined network (SDN). In DoS attack, the network bandwidth is acquired by disrupting the services of the server by abruptly increasing the traffic and making the server unavailable for other users. The most challenging problem of DoS attack is to detect the attack almost instantly and in a precise manner. This paper presents the detection of DoS attacks by using sFlow analyzer, a SDNs flow monitoring tool. In the event of any attack, sFlow collects sample packets from network traffic, analyzes suspicious behavior and creates handling rules which are then sent to the controller. Implementation of DoS attack is carried out by emulating a typical network in Mininet and integrating this with sFlow analyzer. Through the simulated results, the potential DoS victims and attackers are quickly found.

Sie haben noch keine Lizenz? Dann Informieren Sie sich jetzt über unsere Produkte:

Springer Professional "Wirtschaft+Technik"

Online-Abonnement

Mit Springer Professional "Wirtschaft+Technik" erhalten Sie Zugriff auf:

  • über 102.000 Bücher
  • über 537 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Maschinenbau + Werkstoffe
  • Versicherung + Risiko

Jetzt Wissensvorsprung sichern!

Springer Professional "Technik"

Online-Abonnement

Mit Springer Professional "Technik" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 390 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Maschinenbau + Werkstoffe




 

Jetzt Wissensvorsprung sichern!

Springer Professional "Wirtschaft"

Online-Abonnement

Mit Springer Professional "Wirtschaft" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 340 Zeitschriften

aus folgenden Fachgebieten:

  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Versicherung + Risiko




Jetzt Wissensvorsprung sichern!

Literatur
1.
Zurück zum Zitat Ambrosin M, Conti M, De Gaspari F, Poovendran R (2017) Lineswitch: tackling control plane saturation attacks in software-defined networking. IEEE/ACM Trans Netw (TON) 25(2):1206–1219CrossRef Ambrosin M, Conti M, De Gaspari F, Poovendran R (2017) Lineswitch: tackling control plane saturation attacks in software-defined networking. IEEE/ACM Trans Netw (TON) 25(2):1206–1219CrossRef
2.
Zurück zum Zitat Dridi L, Zhani MF (2018) A holistic approach to mitigating DOS attacks in SDN networks. Int J Netw Manag 28(1):e1996CrossRef Dridi L, Zhani MF (2018) A holistic approach to mitigating DOS attacks in SDN networks. Int J Netw Manag 28(1):e1996CrossRef
3.
Zurück zum Zitat Jyothirmai P, Raj JS, Smys S (2017) Secured self organizing network architecture in wireless personal networks. Wirel Pers Commun 96(4):5603–5620CrossRef Jyothirmai P, Raj JS, Smys S (2017) Secured self organizing network architecture in wireless personal networks. Wirel Pers Commun 96(4):5603–5620CrossRef
4.
Zurück zum Zitat Nugraha M, Paramita I, Musa A, Choi D, Cho B (2014) Utilizing OpenFlow and sFlow to detect and mitigate SYN flooding attack, 17(8):988–994 Nugraha M, Paramita I, Musa A, Choi D, Cho B (2014) Utilizing OpenFlow and sFlow to detect and mitigate SYN flooding attack, 17(8):988–994
5.
Zurück zum Zitat Ombase PM et al (2017) Survey on DOS attack challenges in software defined networking. Int J Comput App 975:8887 Ombase PM et al (2017) Survey on DOS attack challenges in software defined networking. Int J Comput App 975:8887
6.
Zurück zum Zitat Othman RA (2000) Understanding the various types of denial of service attack. Bus Week Online. Accessed 12 Feb 2000 Othman RA (2000) Understanding the various types of denial of service attack. Bus Week Online. Accessed 12 Feb 2000
8.
Zurück zum Zitat Scarlato M. Network monitoring in software defined networking (thesis). Accessed 30 Jul 2014 Scarlato M. Network monitoring in software defined networking (thesis). Accessed 30 Jul 2014
9.
Zurück zum Zitat Shang G, Zhe P, Bin X, Aiqun H, Kui R (2017) Flooddefender: protecting data and control plane resources under SDN-aimed DOS attacks. In: INFOCOM 2017-IEEE conference on computer communications. IEEE, pp 1–9 Shang G, Zhe P, Bin X, Aiqun H, Kui R (2017) Flooddefender: protecting data and control plane resources under SDN-aimed DOS attacks. In: INFOCOM 2017-IEEE conference on computer communications. IEEE, pp 1–9
10.
Zurück zum Zitat Sridhar S, Smys S (2016) A hybrid multilevel authentication scheme for private cloud environment. In: 2016 10th international conference on intelligent systems and control (ISCO). IEEE, pp 1–5 Sridhar S, Smys S (2016) A hybrid multilevel authentication scheme for private cloud environment. In: 2016 10th international conference on intelligent systems and control (ISCO). IEEE, pp 1–5
11.
Zurück zum Zitat Stallings W (2015) Foundations of modern networking: SDN, NFV, QoE, IoT, and Cloud. Addison-Wesley Professional Stallings W (2015) Foundations of modern networking: SDN, NFV, QoE, IoT, and Cloud. Addison-Wesley Professional
12.
Zurück zum Zitat Swapna AI, Reza MRH, Aion MK (2016) Security analysis of software defined wireless network monitoring with sFlow and FlowVisor. In: International conference on communication and electronics systems (ICCES). IEEE, pp 1–7 Swapna AI, Reza MRH, Aion MK (2016) Security analysis of software defined wireless network monitoring with sFlow and FlowVisor. In: International conference on communication and electronics systems (ICCES). IEEE, pp 1–7
Metadaten
Titel
Detecting Denial-of-Service Attacks Using sFlow
verfasst von
Shivaraj Hublikar
Vijaya Eligar
Arun Kakhandki
Copyright-Jahr
2020
Verlag
Springer Singapore
DOI
https://doi.org/10.1007/978-981-15-0146-3_46