DocumentCode
2153483
Title
FlowRanger: A request prioritizing algorithm for controller DoS attacks in Software Defined Networks
Author
Wei, Lei ; Fung, Carol
Author_Institution
School of Computer Engineering, Nanyang Technological University, Singapore
fYear
2015
fDate
8-12 June 2015
Firstpage
5254
Lastpage
5259
Abstract
Software Defined Networking (SDN) introduces a new communication network management paradigm and has gained much attention from academia and industry. However, the centralized nature of SDN is a potential vulnerability to the system since attackers may launch denial of services (DoS) attacks against the controller. Existing solutions limit requests rate to the controller by dropping overflowed requests, but they also drop legitimate requests to the controller. To address this problem, we propose FlowRanger, a buffer prioritizing solution for controllers to handle routing requests based on their likelihood to be attacking requests, which derives the trust values of the requesting sources. Based on their trust values, FlowRanger classifies routing requests into multiple buffer queues with different priorities. Thus, attacking requests are served with a lower priority than regular requests. Our simulation results demonstrates that FlowRanger can significantly enhance the request serving rate of regular users under DoS attacks against the controller. To the best of our knowledge, our work is the first solution to battle against controller DoS attacks on the controller side.
Keywords
Computer crime; Next generation networking; Processor scheduling; Routing; Switches;
fLanguage
English
Publisher
ieee
Conference_Titel
Communications (ICC), 2015 IEEE International Conference on
Conference_Location
London, United Kingdom
Type
conf
DOI
10.1109/ICC.2015.7249158
Filename
7249158
Link To Document