Two-Layers DDoS Attack Detection Model Using Machine Learning in Software Defined Networking

Authors: Nguyen Ngoc Tuan*, Nguyen Huu Thanh
https://doi.org/10.51316/jst.166.ssad.2023.33.2.1

Abstract

Software Defined Network is a new architecture designed to make the network infrastructure more flexible and easier to manage. It allows network administrators to configure network parameters as well as integrating new functions using programming languages easily. Thanks to the centralized control paradigm, it is easier to collect information of the entire network, which facilitates the implementation of machine learning algorithms to detect anomaly traffic as well as network attacks. Recently, with the development of machine learning and artificial intelligence, several methods have been applied to detect and mitigate DDoS attacks. However, all of activities from monitoring data, detecting and mitigating the attack consume time and resources. To reduce unnecessary redundancy, in this paper, we divide attack detection into two phases, which are anomaly detection phase with lightweight machine learning algorithm and attack detection phase when anomaly behaviors have been detected. This reduces the in-depth analysis of normal traffic and helps to improve the use of computing resources and data transmission efficiency of the network. By setting up a testbed, we have successfully run this model as well as evaluated the accuracy of the model. The results show that our model can detect attacks quickly and accurately.

Keyword

DDOS detection, SDN, Security, Machine learning
Pages : 1-8

Related Articles:

Authors : Cao Xuân Bình, Vũ Tiến Dũng, Nguyễn Thị Kim Cúc*, Vũ Toàn Thắng
Authors : Do Tran-Truong, Nguyen Xuan Dung, Phuong Xuan Quang, Vinh Tran-Quang*
Authors : Nhu Toan Nguyen, Duc Thinh Le, Manh Cuong Nguyen, Danh Huy Nguyen, Tung Lam Nguyen*
Authors : Van-Vuong Dinh, Van-Long Nguyen, Kim-Chien Hoang, Minh-Duc Duong, Quy-Thinh Dao*