A Research Review on SDN-Based DDOS Attack Detection

Weidong Zhu,Xiujuan Yi
DOI: https://doi.org/10.2991/msmi-17.2017.33
2017-01-01
Abstract:Software definition network (SDN) is a new network architecture, which can realize centralized control of the network by separating the control plane and the data plane. With the introduction of the control plane as a manager of the network, a single point of failure is introduced too. When the network device cannot get access to the SDN controller, the entire network will breakdown. The controller is vulnerable to distributed denial of service (DDOS) attacks, resulting in resource exhaustion, so that the switch cannot get the services of controller. In this paper, different DDOS attack methods are classified according to the different levels of attack and detection positions, and the methods are analyzed and compared. Finally, the problems of DDOS attack detection in SDN are discussed and the potentials for further research are presented.
What problem does this paper attempt to address?