DDoS Attack Detection in SDN Using CUSUM

0Citations
Citations of this article
3Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Software Defined Networking (SDN) is a network paradigm which separates the control plane from data plane. Due to this separation, SDN gives the advantages of programmability, flexibility, and centralized control to the network. However, SDN requires communication between the data plane and control plane, which may create a bottleneck in the network due to limited bandwidth. In addition, there may be a possibility of an attack over centralized controller. Because of the abovementioned requirement and issue, SDN may be a victim of DoS/DDoS attack. In this paper, detection of DDoS attack is carried out by periodically monitoring TCP handshake packets. It is based on TCP protocol behavior. It applies the cumulative sum (CUSUM) algorithm to detect change point in number of half-open connections. It is implemented in the controller. We have compared our work with existing DDoS solutions with CUSUM and shown that our method gives better results.

Author supplied keywords

Cite

CITATION STYLE

APA

Shalini, P. V., Radha, V., & Sanjeevi, S. G. (2021). DDoS Attack Detection in SDN Using CUSUM. In Lecture Notes on Data Engineering and Communications Technologies (Vol. 56, pp. 301–309). Springer Science and Business Media Deutschland GmbH. https://doi.org/10.1007/978-981-15-8767-2_26

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free