• DocumentCode
    2153483
  • Title

    FlowRanger: A request prioritizing algorithm for controller DoS attacks in Software Defined Networks

  • Author

    Wei, Lei ; Fung, Carol

  • Author_Institution
    School of Computer Engineering, Nanyang Technological University, Singapore
  • fYear
    2015
  • fDate
    8-12 June 2015
  • Firstpage
    5254
  • Lastpage
    5259
  • Abstract
    Software Defined Networking (SDN) introduces a new communication network management paradigm and has gained much attention from academia and industry. However, the centralized nature of SDN is a potential vulnerability to the system since attackers may launch denial of services (DoS) attacks against the controller. Existing solutions limit requests rate to the controller by dropping overflowed requests, but they also drop legitimate requests to the controller. To address this problem, we propose FlowRanger, a buffer prioritizing solution for controllers to handle routing requests based on their likelihood to be attacking requests, which derives the trust values of the requesting sources. Based on their trust values, FlowRanger classifies routing requests into multiple buffer queues with different priorities. Thus, attacking requests are served with a lower priority than regular requests. Our simulation results demonstrates that FlowRanger can significantly enhance the request serving rate of regular users under DoS attacks against the controller. To the best of our knowledge, our work is the first solution to battle against controller DoS attacks on the controller side.
  • Keywords
    Computer crime; Next generation networking; Processor scheduling; Routing; Switches;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Communications (ICC), 2015 IEEE International Conference on
  • Conference_Location
    London, United Kingdom
  • Type

    conf

  • DOI
    10.1109/ICC.2015.7249158
  • Filename
    7249158