Chinese Journal of Network and Information Security ›› 2022, Vol. 8 ›› Issue (2): 73-87.doi: 10.11959/j.issn.2096-109x.2022017

• Topic: Cybersecurity——Attack and Defense Technologies • Previous Articles     Next Articles

Defense mechanism of SDN application layer against DDoS attack based on API call management

Yang WANG1, Guangming TANG1, Shuo WANG2, Jiang CHU2   

  1. 1 Information Engineering University, Zhengzhou 450001, China
    2 China Xi’an Satellite Control Center, Xi’an 710043, China
  • Revised:2021-10-20 Online:2022-04-15 Published:2022-04-01
  • Supported by:
    The National Natural Science Foundation of China(61802438)

Abstract:

Due to thelack of strict access control, identity authentication and abnormal call detection, attackers may develop malicious applications easily and then it leads to theabuse of the northbound interface API (application programming interface) accordingly.There are mainly two patterns of DDoS (distributed denial-of-service) attacks against application layer.1) malicious App bypass the security review of the northbound interface and make a large number of calls to some API in a short time, thus causing the controller to crash and paralyzing the whole network; 2) attackers take a legitimate SDN (software defined network) application as the target and make a large number of short-time calls to the specific API needed by the application, which makes the legitimate App unable to call the API normally.Compared with the first pattern, the second one is more subtle.Therefore, it’s necessary to distinguish whether the App is malicious or not, effectively clean the App running on the attacked controller, and redistribute the controller to the legitimate App.Based on the in-depth analysis of the development trend of the current northbound interface, the possible DDoS attack patterns were simulated and practiced.Then a DDoS defense mechanism for SDN application layer was proposed.This mechanism added an App management layer between SDN application layer and control layer.Through reputation management, initial review, mapping allocation, anomaly detection and identification migration of the App, the malicious App attack on SDN can be predicted and resisted.The proposal focused on pre-examination of malicious App before attacks occur, so as to avoid attacks.If the attack has already happened, the operation of cleaning and separating the legitimate App from the malicious App is triggered.Theoretical and experimental results show that the proposed mechanism can effectively avoid DDoS attacks in SDN application layer, and the algorithm runs efficiently.

Key words: DDoS, network security, SDN, northbound interface

CLC Number: 

No Suggested Reading articles found!