DDoS attack mitigation in internet of things using software defined networking

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Securing Internet of Things (IoT) systems is a challenge because of its multiple points of vulnerability. A spate of recent hacks and security breaches has unveiled glaring vulnerabilities in the IoT. Due to the computational and memory requirement constraints associated with anomaly detection algorithms in core networks, commercial in-line (part of the direct line of communication) Anomaly Detection Systems (ADSs) rely on sampling-based anomaly detection approaches to achieve line rates and truly-inline anomaly detection accuracy in real-time. However, packet sampling is inherently a lossy process which might provide an incomplete and biased approximation of the underlying traffic patterns. Moreover, commercial routers uses proprietary software making them closed to be manipulated from the outside. As a result, detecting malicious packets on the given network path is one of the most challenging problems in the field of network security. We argue that the advent of Software Defined Networking (SDN) provides a unique opportunity to effectively detect and mitigate DDoS attacks. Unlike sampling-based approaches for anomaly detection and limitation of proprietary software at routers, we use the SDN infrastructure to relax the sampling-based ADS constraints and collect traffic flow statistics which are maintained at each SDN-enabled switch to achieve high detection accuracy. In order to implement our idea, we discuss how to mitigate DDoS attacks using the features of SDN infrastructure.

Original languageEnglish
Title of host publicationProceedings - 3rd IEEE International Conference on Big Data Computing Service and Applications, BigDataService 2017
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages271-276
Number of pages6
ISBN (Electronic)9781509063185
DOIs
StatePublished - 8 Jun 2017
Event3rd IEEE International Conference on Big Data Computing Service and Applications, BigDataService 2017 - San Francisco, United States
Duration: 6 Apr 201710 Apr 2017

Publication series

NameProceedings - 3rd IEEE International Conference on Big Data Computing Service and Applications, BigDataService 2017

Conference

Conference3rd IEEE International Conference on Big Data Computing Service and Applications, BigDataService 2017
Country/TerritoryUnited States
CitySan Francisco
Period6/04/1710/04/17

Keywords

  • DDoS attack
  • OpenFlow
  • Software Defined Networking

Fingerprint

Dive into the research topics of 'DDoS attack mitigation in internet of things using software defined networking'. Together they form a unique fingerprint.

Cite this