Please use this identifier to cite or link to this item: https://dspace.iiti.ac.in/handle/123456789/11352
Full metadata record
DC FieldValueLanguage
dc.contributor.authorHubballi, Neminathen_US
dc.contributor.authorPatel, Kanishken_US
dc.date.accessioned2023-02-27T15:27:08Z-
dc.date.available2023-02-27T15:27:08Z-
dc.date.issued2022-
dc.identifier.citationHubballi, N., & Patel, K. (2022). WiP: Control plane saturation attack mitigation in Software defined networks doi:10.1007/978-3-031-23690-7_14 Retrieved from www.scopus.comen_US
dc.identifier.isbn978-3031236891-
dc.identifier.issn0302-9743-
dc.identifier.otherEID(2-s2.0-85145262082)-
dc.identifier.urihttps://doi.org/10.1007/978-3-031-23690-7_14-
dc.identifier.urihttps://dspace.iiti.ac.in/handle/123456789/11352-
dc.description.abstractRecent works have shown that the interaction between control and data plane in the Software Defined Networks can be chocked by an adversary with saturation attack. This attack is generated by sending large number of new flows to a switch exploiting the switch-controller communication. A switch sends a packet-in message to the controller if a new flow is seen. A flux of new flows results in a large number of packet-in messages at the controller. In this paper, we present SaturationGuard which mitigates this attack by adopting an early attack detection method. An anomaly detection method deployed at the controller observes the patterns of packet-in messages and identifies the attack. In particular, we capture normal interaction between switch and controller using the arrival rate of packet-in messages with a probability distribution. To mitigate the attack, we propose to throttle the bandwidth of the affected switch port in proportion to the arrival rate of new flows. We implement a proof of concept solution with Mininet and an external controller and show that SaturationGuard is effective in handling the saturation attacks with early stage detection. © 2022, The Author(s), under exclusive license to Springer Nature Switzerland AG.en_US
dc.language.isoenen_US
dc.publisherSpringer Science and Business Media Deutschland GmbHen_US
dc.sourceLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)en_US
dc.subjectAnomaly detectionen_US
dc.subjectBandwidthen_US
dc.subjectProbability distributionsen_US
dc.subjectSoftware defined networkingen_US
dc.subjectAnomaly detectionen_US
dc.subjectArrival ratesen_US
dc.subjectBandwidth throttlingen_US
dc.subjectControl planesen_US
dc.subjectData planesen_US
dc.subjectData-planeen_US
dc.subjectMitigationen_US
dc.subjectSaturation attacksen_US
dc.subjectSoftware-defined networkingsen_US
dc.subjectSoftware-defined networksen_US
dc.subjectControllersen_US
dc.titleWiP: Control Plane Saturation Attack Mitigation in Software Defined Networksen_US
dc.typeConference Paperen_US
Appears in Collections:Department of Computer Science and Engineering

Files in This Item:
There are no files associated with this item.


Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.

Altmetric Badge: