DOI QR코드

DOI QR Code

Enhancement of Sampling Based DDoS Detecting System for SDN

소프트웨어 정의 네트워크를 위한 샘플링 기반 서비스거부공격 탐지 시스템 개선

  • Nguyen, Sinhngoc (Dept. of Electronics and Computer Engineering, Chonnam National University) ;
  • Choi, Jintae (Dept. of Electronics and Computer Engineering, Chonnam National University) ;
  • Kim, Kyungbaek (Dept. of Electronics and Computer Engineering, Chonnam National University)
  • 뉘엔신응억 (전남대학교 전자컴퓨터공학부) ;
  • 최진태 (전남대학교 전자컴퓨터공학부) ;
  • 김경백 (전남대학교 전자컴퓨터공학부)
  • Published : 2017.04.27

Abstract

Nowadays, Distributed Denial of Service (DDoS) attacks have gained increasing popularity and have been a major factor in a number of massive cyber-attacks. It could easily exhaust the computing and communicating resources of a victim within a short period of time. Therefore, we have to find the method to detect and prevent the DDoS attack. Recently, there have been some researches that provide the methods to resolve above problem, but it still gets some limitations such as low performance of detecting and preventing, scope of method, most of them just use on cloud server instead of network, and the reliability in the network. In this paper, we propose solutions for (1) handling multiple DDoS attacks from multiple IP address and (2) handling the suspicious attacks in the network. For the first solution, we assume that there are multiple attacks from many sources at a times, it should be handled to avoid the conflict when we setup the preventing rule to switches. In the other, there are many attacks traffic with the low volume and same destination address. Although the traffic at each node is not much, the traffic at the destination is much more. So it is hard to detect that suspicious traffic with the sampling based method at each node, our method reroute the traffic to another server and make the analysis to check it deeply.

Keywords