科研速览 · Science Skim继续刷下去 · Keep skimming →
◆ IEEE Transactions on Networking2026-01-01· Computer science

MWD-CFM: Detection and Mitigation of DDoS Attack Against SDN Flow Tables

Dan Tang, Chenguang Zuo, Xinmeng Li, Siyuan Wang, Wei Liang, Keqin Li, Jiliang Zhang

原始摘要(英文原文)· Original abstract
The decoupling of SDN control plane and data plane allows control to be carried out independently, enhancing the programmability and manageability of the whole network. However, though this new architecture brings convenience for control, it also sets a pool for attacks. Due to the expensive and resource-consumption characteristics, SDN switches usually have a limited ternary content addressable memory to cache the flow rules in the data plane. Attackers can launch a space-consuming attack to maliciously preempt the flow table, forcing switches to reduce the quality of service. Among them, DDoS attacks should be taken seriously, especially the low-rate ones that have a lower attack rate with stronger concealment. In this paper, an architecture named MWD-CFM is proposed to protect against low-rate DDoS attacks in the switch flow tables. Multi-windows work collaboratively to improve detection performance. The feature of flow rules is corrected to do better classification, improving the effectiveness of attack traffic removal. Experiments based on real network topology and datasets are conducted to verify the deployment of MWD-CFM. Results prove that our architecture can greatly reduce the survival time of attack flows and ensure the availability of flow tables for legitimate services.
读原文 · Read the paper ↗

AI 追问PRO

登录后使用 AI 追问

讨论区

登录后参与讨论

相关论文 · Related

MWD-CFM: Detection and Mitigation of DDoS Attack Against SDN Flow Tables — 科研速览 Science Skim