Software defined network-based HTTP flooding attack defender

Journal Article (2022)
Author(s)

Reza Mohammadi (Bu-Ali Sina University, Hamadan)

C. Lal (TU Delft - Cyber Security)

Mauro Conti (TU Delft - Cyber Security, University of Padua)

Lokesh Sharma (Manipal University Jaipur)

Research Group
Cyber Security
Copyright
© 2022 Reza Mohammadi, C. Lal, M. Conti, Lokesh Sharma
DOI related publication
https://doi.org/10.1016/j.compeleceng.2022.108019
More Info
expand_more
Publication Year
2022
Language
English
Copyright
© 2022 Reza Mohammadi, C. Lal, M. Conti, Lokesh Sharma
Research Group
Cyber Security
Bibliographical Note
Green Open Access added to TU Delft Institutional Repository 'You share, we take care!' - Taverne project https://www.openaccess.nl/en/you-share-we-take-care Otherwise as indicated in the copyright section: the publisher is the copyright holder of this work and the author uses the Dutch legislation to make this work public.@en
Volume number
101
Reuse Rights

Other than for strictly personal use, it is not permitted to download, forward or distribute the text or part of it, without the consent of the author(s) and/or copyright holder(s), unless the work is under an open content license such as Creative Commons.

Abstract

In recent years, the explosive growth of the Internet has led to an increment in the number of Distributed Denial of Service (DDoS) attacks. HTTP Flooding is a critical DDoS attack that targets HTTP servers to prohibit users from receiving HTTP services. Moreover, it saturates the link bandwidth and consumes network resources. Because the attack is launched at the application layer, it is difficult to defend against it using current countermeasures such as firewall or Intrusion Prevention System (IPS). In this paper, we propose SHFD, which leverages the Software-Defined Networking (SDN) paradigm to mitigate HTTP flooding attacks. We implement SHFD as a defender module on the SDN controller to detect and mitigate the attack in the first place. Experimental results gathered from Mininet confirm that SHFD brings a significant improvement of 13% in detection time and 29% in the number of blocked malicious flows compared to the state-of-the-art approaches.

Files

1_s2.0_S0045790622002841_main.... (pdf)
(pdf | 1.5 Mb)
- Embargo expired in 13-11-2022
License info not available