Font Size: a A A

Research On DDoS Attack Detection And Defense Scheme In SDN Environment

Posted on:2024-04-29Degree:MasterType:Thesis
Country:ChinaCandidate:S L WangFull Text:PDF
GTID:2568307175973069Subject:Master of Electronic Information (Professional Degree)
Abstract/Summary:
The SDN architecture changes the feature of network design and management,decoupling data planes from the control plane,and introducing network programmability to reduce the difficulty for technicians to deploy new services in the network.In the face of the strong vitality of SDN in the future development of the network,its security issues also cause concern.As one of the typical consumable attacks means,the DDo S causes greater damage to SDN architecture,longer duration,and wider scope than traditional distributed network architecture.Therefore,this paper researches the detection and defense scheme of DDo S attacks in an SDN environment.The main work is as follows:(1)Aiming at the problems of low accuracy of the Shannon entropy detection method and large resource utilization of the neural network method,a DDo S attack detection scheme based on the combination of generalized entropy and Adam-DNN is proposed.In the early pre-detection based on generalized entropy,the destination IP address of unmatched packets is first extracted,then the generalized entropy of the destination IP address within the current sampling period is calculated,and the SDN environment is set up on Mininet simulation platform for threshold selection.Finally,the generalized entropy within the current sampling period is compared with the threshold to output normal,abnormal,and attack traffic.The simulation results show that the generalized entropy-based pre-detection scheme has higher detection sensitivity than the Shannon entropy detection scheme.(2)Aiming at the problem of low detection accuracy due to single feature detection based on the generalized entropy method,a heavy-weight secondary detection based on Adam-DNN is introduced.In the secondary detection,only abnormal traffic output by the pre-detection module is detected.The 6-element traffic characteristics of abnormal traffic are extracted as the input of Adam-DNN,and the normal or attack traffic is eventually output.The simulation results show that compared with the traditional machine learning,deep neural network,and Shannon entropy detection schemes,this scheme can effectively avoid the problems of low accuracy of information entropy detection and large utilization of neural network detection resources,improve the accuracy and reduce the utilization rate of the controller.(3)Aiming at the problem that traditional moving target defense technology is difficult to cope with scanning attacks,an active defense scheme based on the detection results of the threat detection module adaptively adjusts the jump strategy is proposed.When the threat detection module detects the abnormal current network scan,the strategy adjustment module adaptive jump space in the end address information and period to ensure system safety while adding a semi-end address hopping strategy based on communication to reduce defense spending.The simulation results show that compared with the traditional hopping scheme,this scheme can effectively avoid the problem that the traditional hopping strategy is fixed,which leads to the easy attacker to obtain information,reduce the scanning success rate of the attacker,and reduce the defense cost.
Keywords/Search Tags:SDN, DDoS, Traffic detection, MTD, Adaptive strategy
Related items