Journal on Communications ›› 2019, Vol. 40 ›› Issue (3): 116-124.doi: 10.11959/j.issn.1000-436x.2019067

• Papers • Previous Articles     Next Articles

UDM:NFV-based prevention mechanism against DDoS attack on SDN controller

Hongyan QIAN,Hao XUE,Ming CHEN()   

  1. College of Computer Science and Technology,Nanjing University of Aeronautics and Astronautics,Nanjing 211106,China
  • Revised:2019-01-03 Online:2019-03-01 Published:2019-04-04
  • Supported by:
    The National Natural Science Foundation of China(61772271);The National Natural Science Foundation of China(61379149)

Abstract:

DDoS attack extensively existed have been mortal threats for the software-defined networking (SDN) controllers and there is no any security mechanism which can prevent them yet.Combining SDN and network function virtualization (NFV),a novel preventing mechanism against DDoS attacks on SDN controller called upfront detection middlebox (UDM) was proposed.The upfront detection middlebox was deployed between SDN switch interfaces and user hosts distributed,and DDoS attack packets were detected and denied.An NFV-based method of implementing the upfront middlebox was put forward,which made the UDM mechanism be economical and effective.A prototype system based on this mechanism was implemented and lots experiments were tested.The experimental results show that the UDM mechanism based on NFV can real-time and effectively detect and prevent against DDoS attacks on SDN controllers.

Key words: DDoS attack, controller security, SDN and NFV, upfront detection middlebox

CLC Number: 

No Suggested Reading articles found!