Skip to main navigation Skip to search Skip to main content

SDN-based network security functions for effective DDoS attack mitigation

  • Sungkyunkwan University

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Distributed Denial of Service (DDoS) attack has been bringing serious security concerns on banks, finance incorporation, public institutions, and data centers. Also, the emerging wave of Internet of Things (IoT) raises new concerns on the smart devices. Software Defined Networking (SDN) and Network Functions Virtualization (NFV) have provided a new paradigm for network security. In this paper, we propose a new method to efficiently prevent DDoS attacks, based on a SDN/NFV framework. To resolve the problem that normal packets are blocked due to the inspection on suspicious packets, we developed a threshold-based method that provides a client with an efficient, fast DDoS attack mitigation. In addition, we use open source code to develop the security functions in order to implement our solution for SDN-based network security functions. The source code is based on NETCONF protocol [1] and YANG Data Model [2].

Original languageEnglish
Title of host publicationInternational Conference on Information and Communication Technology Convergence
Subtitle of host publicationICT Convergence Technologies Leading the Fourth Industrial Revolution, ICTC 2017
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages834-839
Number of pages6
ISBN (Electronic)9781509040315
DOIs
StatePublished - 12 Dec 2017
Event8th International Conference on Information and Communication Technology Convergence, ICTC 2017 - Jeju Island, Korea, Republic of
Duration: 18 Oct 201720 Oct 2017

Publication series

NameInternational Conference on Information and Communication Technology Convergence: ICT Convergence Technologies Leading the Fourth Industrial Revolution, ICTC 2017
Volume2017-December

Conference

Conference8th International Conference on Information and Communication Technology Convergence, ICTC 2017
Country/TerritoryKorea, Republic of
CityJeju Island
Period18/10/1720/10/17

Keywords

  • Distributed Denial of Service
  • Netconf & YANG
  • Network Function Virtual
  • Software Defined Network
  • Suricata

Fingerprint

Dive into the research topics of 'SDN-based network security functions for effective DDoS attack mitigation'. Together they form a unique fingerprint.

Cite this