Cam: A Counting Bloom Filter Based Attack Mitigation System For Sdn

Xiaofan Chen,Shunzheng Yu
2016-01-01
Abstract:SDN is now suffer from not only the attacks in legacy network, e.g. DDoS and IP scan, but also the SDN-specific attack, e.g. data-to-control plan saturation attack. It is imperative to develop effective SDN-supported approaches for intrusion containment. We propose CAM, i.e. a counting bloom filter based attack mitigation system for SDN, to protect SDN from such attacks. CAM used counting bloom filter to block suspicious source and destination IP pairs at low cost. It can mitigate more than one attack types at the source side, including the legacy attacks and SDN-specific attacks. It is robust for its distributed architecture. The simulation validates its effectiveness.
What problem does this paper attempt to address?