Skip to main navigation Skip to search Skip to main content

DDoS Attack Early Detection and Mitigation System on SDN using Random Forest Algorithm and Ryu Framework

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Distributed Denial of Service (DDoS) attacks became a true threat to network infrastructure. DDoS attacks are capable of inflicting major disruption to the information communication technology infrastructure. DDoS attacks aim to paralyze networks by overloading servers, network links, and network devices with illegitimate traffic. Therefore, it is important to detect and mitigate DDoS attacks to reduce the impact of DDoS attacks. In traditional networks, the hardware and software to detect and mitigate DDoS attacks are expensive and difficult to deploy. Software-Defined Network (SDN) is a new paradigm in network architecture by separating the control plane and data plane, thereby increasing scalability, flexibility, control, and network management. Therefore, SDN can dynamically change DDoS traffic forwarding rules and improve network security. In this study, a DDoS attack detection and mitigation system was built on the SDN architecture using the random forest machine-learning algorithm. The random forest algorithm will classify normal and attack packets based on flow entries. If packets are classified as a DDoS attack, it will be mitigated by adding flow rules to the switch. Based on tests that have been done, the detection system can detect DDoS attacks with an average accuracy of 98.38% and an average detection time of 36 ms. Then the mitigation system can mitigate DDoS attacks with an average mitigation time of 1179 ms and can reduce the average number of attack packets that enter the victim host by 15672 packets and can reduce the average number of CPU usage on the controller by 44,9%.

Original languageEnglish
Title of host publicationProceedings of the 8th International Conference on Computer and Communication Engineering, ICCCE 2021
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages178-183
Number of pages6
ISBN (Electronic)9781728110646
DOIs
Publication statusPublished - 22 Jun 2021
Event8th International Conference on Computer and Communication Engineering, ICCCE 2021 - Kuala Lumpur, Malaysia
Duration: 22 Jun 202123 Jun 2021

Publication series

NameProceedings of the 8th International Conference on Computer and Communication Engineering, ICCCE 2021

Conference

Conference8th International Conference on Computer and Communication Engineering, ICCCE 2021
Country/TerritoryMalaysia
CityKuala Lumpur
Period22/06/2123/06/21

UN SDGs

This output contributes to the following UN Sustainable Development Goals (SDGs)

  1. SDG 9 - Industry, Innovation, and Infrastructure
    SDG 9 Industry, Innovation, and Infrastructure

Keywords

  • DDoS
  • Machine Learning
  • Random Forest Algorithm
  • Ryu Framework
  • SDN

Fingerprint

Dive into the research topics of 'DDoS Attack Early Detection and Mitigation System on SDN using Random Forest Algorithm and Ryu Framework'. Together they form a unique fingerprint.

Cite this