Thesis Open Access
MULATU MEKONNEN
<?xml version='1.0' encoding='UTF-8'?> <record xmlns="http://www.loc.gov/MARC21/slim"> <leader>00000nam##2200000uu#4500</leader> <controlfield tag="005">20250114084425.0</controlfield> <controlfield tag="001">5778</controlfield> <datafield tag="856" ind1="4" ind2=" "> <subfield code="s">647925</subfield> <subfield code="z">md5:d45cbd5fd89e1d88df48cadeabb670f7</subfield> <subfield code="u">https://zenodo.org/record/5778/files/f1042664640.pdf</subfield> </datafield> <datafield tag="542" ind1=" " ind2=" "> <subfield code="l">open</subfield> </datafield> <datafield tag="260" ind1=" " ind2=" "> <subfield code="c">2019-06-01</subfield> </datafield> <datafield tag="909" ind1="C" ind2="O"> <subfield code="p">user-dbu</subfield> <subfield code="p">user-zenodo</subfield> <subfield code="o">oai:zenodo.org:5778</subfield> </datafield> <datafield tag="100" ind1=" " ind2=" "> <subfield code="a">MULATU MEKONNEN</subfield> </datafield> <datafield tag="245" ind1=" " ind2=" "> <subfield code="a">Internet Protocol (IP)-Based Distributed Denial of Server (DDoS) Attack Detection and Mitigation for Software Defined Networking (SDN) Controller</subfield> </datafield> <datafield tag="980" ind1=" " ind2=" "> <subfield code="a">user-dbu</subfield> </datafield> <datafield tag="980" ind1=" " ind2=" "> <subfield code="a">user-zenodo</subfield> </datafield> <datafield tag="540" ind1=" " ind2=" "> <subfield code="u">http://www.opendefinition.org/licenses/cc-by</subfield> <subfield code="a">Creative Commons Attribution</subfield> </datafield> <datafield tag="650" ind1="1" ind2="7"> <subfield code="a">cc-by</subfield> <subfield code="2">opendefinition.org</subfield> </datafield> <datafield tag="520" ind1=" " ind2=" "> <subfield code="a"><p>Software-defined networking architectural framework eases the life of the network<br> administrators by isolating the data plane from the control plane. This facilitates<br> easy configuration of the network, provides a programmable interface for developing<br> applications related to management, security, logging etc. and the centralized logical<br> controller gives more control over the entire network, which has the total visibility<br> of the network.<br> These advantages of SDN also expose the network to the vulnerabilities and the<br> impact of the attacks are much severe when compared to conventional networks,<br> where the network devices in itself provided protection from the attacks and limits<br> the scope of the attacks.<br> In this paper, we explore various attacks that can be launched on SDN at different<br> layers. We also evaluate some of the existing security methods in mitigating the<br> attacks. We also explore a possible solution to prevent DDoS attacks using entropy.<br> A Distributed Denial of Service (DDoS) attack is a DoS attack utilizing multiple<br> distributed attack sources. Every network in the system has an entropy. Increase<br> in randomness causes decrease in entropy. To mitigate this threat, this project<br> proposes to use the central control of SDN for attack detection and introduces a<br> solution that is effective and lightweight in terms of the resources that it uses.<br> More precisely, this project shows how DDoS attacks can exhaust controller resources<br> and provides a solution to detect such attacks based on the entropy variation of<br> the destination IP address. Based on this value if it drops below threshold , we are<br> blocking the specific port in the switch and bring the port down. This method is able<br> to detect DDoS within the first five hundred packets of the attack traffic</p></subfield> </datafield> <datafield tag="773" ind1=" " ind2=" "> <subfield code="n">doi</subfield> <subfield code="i">isVersionOf</subfield> <subfield code="a">10.20372/nadre:5777</subfield> </datafield> <datafield tag="024" ind1=" " ind2=" "> <subfield code="a">10.20372/nadre:5778</subfield> <subfield code="2">doi</subfield> </datafield> <datafield tag="980" ind1=" " ind2=" "> <subfield code="a">publication</subfield> <subfield code="b">thesis</subfield> </datafield> </record>
All versions | This version | |
---|---|---|
Views | 0 | 0 |
Downloads | 0 | 0 |
Data volume | 0 Bytes | 0 Bytes |
Unique views | 0 | 0 |
Unique downloads | 0 | 0 |