Thesis Open Access
MULATU MEKONNEN
<?xml version='1.0' encoding='UTF-8'?>
<record xmlns="http://www.loc.gov/MARC21/slim">
<leader>00000nam##2200000uu#4500</leader>
<controlfield tag="005">20250114084425.0</controlfield>
<controlfield tag="001">5778</controlfield>
<datafield tag="856" ind1="4" ind2=" ">
<subfield code="s">647925</subfield>
<subfield code="z">md5:d45cbd5fd89e1d88df48cadeabb670f7</subfield>
<subfield code="u">https://zenodo.org/record/5778/files/f1042664640.pdf</subfield>
</datafield>
<datafield tag="542" ind1=" " ind2=" ">
<subfield code="l">open</subfield>
</datafield>
<datafield tag="260" ind1=" " ind2=" ">
<subfield code="c">2019-06-01</subfield>
</datafield>
<datafield tag="909" ind1="C" ind2="O">
<subfield code="p">user-dbu</subfield>
<subfield code="p">user-zenodo</subfield>
<subfield code="o">oai:zenodo.org:5778</subfield>
</datafield>
<datafield tag="100" ind1=" " ind2=" ">
<subfield code="a">MULATU MEKONNEN</subfield>
</datafield>
<datafield tag="245" ind1=" " ind2=" ">
<subfield code="a">Internet Protocol (IP)-Based Distributed Denial of Server (DDoS) Attack Detection and Mitigation for Software Defined Networking (SDN) Controller</subfield>
</datafield>
<datafield tag="980" ind1=" " ind2=" ">
<subfield code="a">user-dbu</subfield>
</datafield>
<datafield tag="980" ind1=" " ind2=" ">
<subfield code="a">user-zenodo</subfield>
</datafield>
<datafield tag="540" ind1=" " ind2=" ">
<subfield code="u">http://www.opendefinition.org/licenses/cc-by</subfield>
<subfield code="a">Creative Commons Attribution</subfield>
</datafield>
<datafield tag="650" ind1="1" ind2="7">
<subfield code="a">cc-by</subfield>
<subfield code="2">opendefinition.org</subfield>
</datafield>
<datafield tag="520" ind1=" " ind2=" ">
<subfield code="a"><p>Software-defined networking architectural framework eases the life of the network<br>
administrators by isolating the data plane from the control plane. This facilitates<br>
easy configuration of the network, provides a programmable interface for developing<br>
applications related to management, security, logging etc. and the centralized logical<br>
controller gives more control over the entire network, which has the total visibility<br>
of the network.<br>
These advantages of SDN also expose the network to the vulnerabilities and the<br>
impact of the attacks are much severe when compared to conventional networks,<br>
where the network devices in itself provided protection from the attacks and limits<br>
the scope of the attacks.<br>
In this paper, we explore various attacks that can be launched on SDN at different<br>
layers. We also evaluate some of the existing security methods in mitigating the<br>
attacks. We also explore a possible solution to prevent DDoS attacks using entropy.<br>
A Distributed Denial of Service (DDoS) attack is a DoS attack utilizing multiple<br>
distributed attack sources. Every network in the system has an entropy. Increase<br>
in randomness causes decrease in entropy. To mitigate this threat, this project<br>
proposes to use the central control of SDN for attack detection and introduces a<br>
solution that is effective and lightweight in terms of the resources that it uses.<br>
More precisely, this project shows how DDoS attacks can exhaust controller resources<br>
and provides a solution to detect such attacks based on the entropy variation of<br>
the destination IP address. Based on this value if it drops below threshold , we are<br>
blocking the specific port in the switch and bring the port down. This method is able<br>
to detect DDoS within the first five hundred packets of the attack traffic</p></subfield>
</datafield>
<datafield tag="773" ind1=" " ind2=" ">
<subfield code="n">doi</subfield>
<subfield code="i">isVersionOf</subfield>
<subfield code="a">10.20372/nadre:5777</subfield>
</datafield>
<datafield tag="024" ind1=" " ind2=" ">
<subfield code="a">10.20372/nadre:5778</subfield>
<subfield code="2">doi</subfield>
</datafield>
<datafield tag="980" ind1=" " ind2=" ">
<subfield code="a">publication</subfield>
<subfield code="b">thesis</subfield>
</datafield>
</record>
| All versions | This version | |
|---|---|---|
| Views | 0 | 0 |
| Downloads | 0 | 0 |
| Data volume | 0 Bytes | 0 Bytes |
| Unique views | 0 | 0 |
| Unique downloads | 0 | 0 |