Distributed Denial of Service (DDoS) attacks are one of the biggest concerns for security professionals. Traditional middle-box based DDoS attack defense is lack of network-wide monitoring flexibility. With the development of software-defined networking (SDN), it becomes prevalent to exploit centralized controllers to defend against DDoS attacks. However, current solutions suffer with serious southbound communication overhead and detection delay. In this paper, we propose a cross-plane DDoS attack defense framework in SDN, called OverWatch, which exploits collaborative intelligence between data plane and control plane with high defense efficiency. Attack detection and reaction are two key procedures of the proposed framework. We develop a collaborative DDoS attack detection mechanism, which consists of a coarse-grained flow monitoring algorithm on the data plane and a fine-grained machine learning based attack classification algorithm on the control plane. We propose a novel defense strategy offloading mechanism to dynamically deploy defense applications across the controller and switches, by which rapid attack reaction and accurate botnet location can be achieved. We conduct extensive experiments on a real-world SDN network. Experimental results validate the efficiency of our proposed OverWatch framework with high detection accuracy and real-time DDoS attack reaction, as well as reduced communication overhead on SDN southbound interface.
from #AlexandrosSfakianakis via Alexandros G.Sfakianakis on Inoreader http://ift.tt/2n5LSrs
via IFTTT
Εγγραφή σε:
Σχόλια ανάρτησης (Atom)
Δημοφιλείς αναρτήσεις
-
Abstract Recent updating of the World Health Organization (WHO) classification of central nervous system (CNS) tumors in 2016 demonstrates...
-
In our previous work, the dichloromethane-methanol (1:1 v/v) extract, fractions and isolated compounds from Polyscias fulva stem bark showed...
-
Background Agricultural work can expose workers to increased risk of heat strain and volume depletion due to repeated exposures to high ambi...
-
Cincinnati.com No fooling; go get your head (and neck) examined for free Cincinnati.com Thursday, get your head examined. UC Health ...
-
Nursing students' perceptions of a video-based serious game's educational value: A pilot study. Nurse Educ Today. 2017 Dec 28;...
-
Anaphora is a rhetorical term for the repetition of a word or phrase at the beginning of successive clauses or verses. from #AlexandrosSfa...
-
Abstract We introduce a novel diagnostic Visual Voiding Device (VVD), which has the ability to visually document urinary voiding events an...
-
Method combines radiomics with three - compartment breast image analysis of dual - energy mammography (Source: The Doctors Lounge - Oncology...
-
Cone beam computerized tomography (CBCT) has been widely used in dental implanting. However, the local hospitals usually don’t have access t...
Δεν υπάρχουν σχόλια:
Δημοσίευση σχολίου