Title :
Leveraging SDN for Efficient Anomaly Detection and Mitigation on Legacy Networks
Author :
Giotis, Kostas ; Androulidakis, G. ; Maglaris, Vasilis
Author_Institution :
Network Manage. & Optimal Design Lab. (NETMODE), Nat. Tech. Univ. of Athens (NTUA), Athens, Greece
Abstract :
In this paper, we investigate the applicability of Software-Defined Networking (SDN), and specifically the use of the OpenFlow protocol as a means to enhance the legacy Remote Triggered Black-Hole (RTBH) routing approach, towards Distributed Denial of Service (DDoS) attack mitigation. More specifically, we exploit the network programmability of OpenFlow to match and handle traffic on a per-flow level, in order to preserve normal operation of the victim, while pushing the mitigation process upstream towards the edge of the network. To this end, we implemented and evaluated a sketch-based anomaly detection and identification mechanism, capable of pinpointing the victim and remotely triggering the mitigation of the offending network traffic. The evaluation is based on the combination of datasets containing real DDoS attacks and normal background traffic from an operational university campus network. Our results demonstrated that the proposed approach succeeds in identifying the victim of the attack and efficiently filtering the malicious sources.
Keywords :
computer network security; routing protocols; software defined networking; DDoS attack mitigation; OpenFlow protocol; RTBH routing; SDN; anomaly detection; distributed denial of service; legacy networks; remote triggered black-hole routing; software-defined networking; Computer crime; IP networks; Image edge detection; Protocols; Radiation detectors; Switches; Telecommunication traffic; Anomaly Detection; Attack Mitigation; DDoS; OpenFlow; RTBH; SDN; Software Defined Networking; sFlow;
Conference_Titel :
Software Defined Networks (EWSDN), 2014 Third European Workshop on
Conference_Location :
Budapest
DOI :
10.1109/EWSDN.2014.24