Yayınlanmış 1 Ocak 2018
| Sürüm v1
Dergi makalesi
Açık
JESS: Joint Entropy-Based DDoS Defense Scheme in SDN
Oluşturanlar
- 1. Univ Oxford, Dept Comp Sci, Oxford OX1 2JD, England
- 2. Bogazici Univ, Dept Comp Engn, TR-34342 Istanbul, Turkey
- 3. Zurich Univ Appl Sci ZHAW, Inst Appl Informat Technol InIT, CH-8401 Winterthur, Switzerland
Açıklama
Software-defined networking (SDN) is a communication paradigm that brings cost efficiency and flexibility through software-defined functions resident on centralized controllers. Although SDN applications are introduced in a limited scope with related technologies still under development, operational SDN networks already face major security threats. Therefore, comprehensive and efficient solutions are crucial. Especially, large-scale security threats such as distributed-denial-of-service (DDoS) attacks are jeopardizing safety and availability of data and services in these systems. A DDoS attack is aimed at making resources unavailable to legitimate users via overloading systems with excessive superfluous traffic from distributed sources. In this paper, we describe and evaluate a joint entropy-based security scheme (JESS) to enhance the SDN security with the aim of a reinforced SDN architecture against DDoS attacks. In particular, our proposed model devises a statistical solution to detect and mitigate these hazards. To the best of our knowledge, JESS is the first model that utilizes joint entropy for DDoS detection and mitigation in the SDN environment. Since it relies on a statistical model, it mitigates not only known attacks but also unfamiliar types in an efficient manner.
Dosyalar
bib-247077be-5dbb-4e19-b51e-193d7f5da1f1.txt
Dosyalar
(174 Bytes)
| Ad | Boyut | Hepisini indir |
|---|---|---|
|
md5:f9e2f8d8bc87aa8498632ac8feadb23f
|
174 Bytes | Ön İzleme İndir |