A DDoS Attack Detection and Mitigation System in SDN
摘要
As the central control hub in the SDN, the SDN controller faces various network threats. DDoS attacks, due to their powerful destructive capabilities, have garnered significant attention from the cybersecurity community. This paper extracts features from real-time attack traffic monitored in an SDN environment, using reversible flow as an important evaluation indicator, while also tracking the reverse flow ratio of the attack traffic. By utilizing this indicator and conducting user behavior statistical analysis of the source IPs of the attack traffic, the system assesses the malicious level of the attack traffic and applies mitigation measures accordingly. This results in a detection and mitigation system capable of autonomously and quickly identifying DDoS attacks. Experimental results show that this system can effectively and swiftly detect and mitigate DDoS attacks in an SDN environment. Additionally, using reversible flow as a characteristic value results in higher accuracy, enhancing the detection and handling capabilities for DDoS attacks.