• DocumentCode
    3683046
  • Title

    SDSNM: A Software-Defined Security Networking Mechanism to Defend against DDoS Attacks

  • Author

    Xiulei Wang; Ming Chen; Changyou Xing

  • Author_Institution
    Coll. of Command Inf. Syst., PLA Univ. of Sci. &
  • fYear
    2015
  • Firstpage
    115
  • Lastpage
    121
  • Abstract
    The Distributed Denial of Service (DDoS) attack has seriously harmed network availability over decades and there is still no effective defense mechanism. The emerging software-defined networking (SDN) gives a new way to rethink the defense of DDoS attacks. In this paper, we first modeled DDoS attacks from the perspective of network architecture. Then a software-defined security networking mechanism (SDSNM) was proposed to remove or restrict these necessary conditions which were summarized from the model. The SDSNM is mainly implemented at the edge SDN networks as well as inherits the infrastructure of IP core network. The Cloud computing and Chord technologies were applied to solve the expansibility and consistency problems. Experiments based on the prototype proved that the brand new mechanism was feasible and incrementally deployable. DDoS attacks were unable to be launched if strict access control policies were used. The attacker along with hosts in botnet can be located quickly and accurately when loose access control policies were used.
  • Keywords
    "Computer crime","DH-HEMTs","Access control","Switches","IP networks","Authentication"
  • Publisher
    ieee
  • Conference_Titel
    Frontier of Computer Science and Technology (FCST), 2015 Ninth International Conference on
  • Type

    conf

  • DOI
    10.1109/FCST.2015.27
  • Filename
    7314660