DocumentCode :
2153483
Title :
FlowRanger: A request prioritizing algorithm for controller DoS attacks in Software Defined Networks
Author :
Wei, Lei ; Fung, Carol
Author_Institution :
School of Computer Engineering, Nanyang Technological University, Singapore
fYear :
2015
fDate :
8-12 June 2015
Firstpage :
5254
Lastpage :
5259
Abstract :
Software Defined Networking (SDN) introduces a new communication network management paradigm and has gained much attention from academia and industry. However, the centralized nature of SDN is a potential vulnerability to the system since attackers may launch denial of services (DoS) attacks against the controller. Existing solutions limit requests rate to the controller by dropping overflowed requests, but they also drop legitimate requests to the controller. To address this problem, we propose FlowRanger, a buffer prioritizing solution for controllers to handle routing requests based on their likelihood to be attacking requests, which derives the trust values of the requesting sources. Based on their trust values, FlowRanger classifies routing requests into multiple buffer queues with different priorities. Thus, attacking requests are served with a lower priority than regular requests. Our simulation results demonstrates that FlowRanger can significantly enhance the request serving rate of regular users under DoS attacks against the controller. To the best of our knowledge, our work is the first solution to battle against controller DoS attacks on the controller side.
Keywords :
Computer crime; Next generation networking; Processor scheduling; Routing; Switches;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Communications (ICC), 2015 IEEE International Conference on
Conference_Location :
London, United Kingdom
Type :
conf
DOI :
10.1109/ICC.2015.7249158
Filename :
7249158
Link To Document :
بازگشت