首页 | 本学科首页   官方微博 | 高级检索  
     


DDoS attack protection in the era of cloud computing and Software-Defined Networking
Affiliation:1. School of Information Science and Technology, Dalian Maritime University, Dalian 116026, China;2. School of Information Science and Engineering, Dalian Polytechnic University, Dalian 116034, China;3. School of Computer Science and Technology, Dalian University of Technology, Dalian 116024, China;1. Central University of Rajasthan, Ajmer, India;2. Malaviya National Institute of Technology, Jaipur, India;3. Indian Institute of Technology, Kanpur, India;4. University of Padua, Padua, Italy
Abstract:Cloud computing has become the real trend of enterprise IT service model that offers cost-effective and scalable processing. Meanwhile, Software-Defined Networking (SDN) is gaining popularity in enterprise networks for flexibility in network management service and reduced operational cost. There seems a trend for the two technologies to go hand-in-hand in providing an enterprise’s IT services. However, the new challenges brought by the marriage of cloud computing and SDN, particularly the implications on enterprise network security, have not been well understood. This paper sets to address this important problem.We start by examining the security impact, in particular, the impact on DDoS attack defense mechanisms, in an enterprise network where both technologies are adopted. We find that SDN technology can actually help enterprises to defend against DDoS attacks if the defense architecture is designed properly. To that end, we propose a DDoS attack mitigation architecture that integrates a highly programmable network monitoring to enable attack detection and a flexible control structure to allow fast and specific attack reaction. To cope with the new architecture, we propose a graphic model based attack detection system that can deal with the dataset shift problem. The simulation results show that our architecture can effectively and efficiently address the security challenges brought by the new network paradigm and our attack detection system can effectively report various attacks using real-world network traffic.
Keywords:DDoS mitigation  Software-Defined Networking  Graphical model
本文献已被 ScienceDirect 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号