Counteracting UDP flooding attacks in SDN

7Citations
Citations of this article
47Readers
Mendeley users who have this article in their library.

Abstract

Software-defined networking (SDN) is a new networking architecture with a centralized control mechanism. SDN has proven to be successful in improving not only the network performance, but also security. However, centralized control in the SDN architecture is associated with new security vulnerabilities. In particular, user-datagram-protocol (UDP) flooding attacks can be easily launched and cause serious packet-transmission delays, controller-performance loss, and even network shutdown. In response to applications in the Internet of Things (IoT) field, this study considers UDP flooding attacks in SDN and proposes two lightweight countermeasures. The first method sometimes sacrifices address-resolution-protocol (ARP) requests to achieve a high level of security. In the second method, although packets must sometimes be sacrificed when undergoing an attack before starting to defend, the detection of the network state can prevent normal packets from being sacrificed. When blocking a network attack, attacks from the affected port are directly blocked without affecting normal ports. The performance and security of the proposed methods were confirmed by means of extensive experiments. Compared with the situation where no defense is implemented, or similar defense methods are implemented, after simulating a UDP flooding attack, our proposed method performed better in terms of the available bandwidth, central-processing-unit (CPU) consumption, and network delay time.

References Powered by Scopus

Software-defined networking (SDN) and distributed denial of service (DDOS) attacks in cloud computing environments: A survey, some research issues, and challenges

714Citations
N/AReaders
Get full text

AVANT-GUARD: Scalable and vigilant switch flow management in software-defined networks

589Citations
N/AReaders
Get full text

A comprehensive study of security of internet-of-things

564Citations
N/AReaders
Get full text

Cited by Powered by Scopus

On the (in)Security of the Control Plane of SDN Architecture: A Survey

24Citations
N/AReaders
Get full text

Detecting Temporal Attacks: An Intrusion Detection System for Train Communication Ethernet Based on Dynamic Temporal Convolutional Network

7Citations
N/AReaders
Get full text

Collaborative Defense Against Hybrid Network Attacks by SDN Controllers and P4 Switches

5Citations
N/AReaders
Get full text

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Cite

CITATION STYLE

APA

Tung, Y. H., Wei, H. C., Ti, Y. W., Tsou, Y. T., Saxena, N., & Yu, C. M. (2020). Counteracting UDP flooding attacks in SDN. Electronics (Switzerland), 9(8), 1–28. https://doi.org/10.3390/electronics9081239

Readers' Seniority

Tooltip

PhD / Post grad / Masters / Doc 8

62%

Lecturer / Post doc 4

31%

Professor / Associate Prof. 1

8%

Readers' Discipline

Tooltip

Computer Science 11

65%

Engineering 5

29%

Business, Management and Accounting 1

6%

Article Metrics

Tooltip
Mentions
Blog Mentions: 1

Save time finding and organizing research with Mendeley

Sign up for free