An Efficient IDS Framework for DDoS Attacks in SDN Environment

The rapid usage of the Internet for the last few decades has lead to the deployment of high-speed networks in commercial and educational institutions. As network traffic is increasing, security challenges are also increasing in the high-speed network. Although the Intrusion Detection System (IDS) ha...

Full description

Bibliographic Details
Main Authors: Josy Elsa Varghese, Balachandra Muniyal
Format: Article
Language:English
Published: IEEE 2021-01-01
Series:IEEE Access
Subjects:
Online Access:https://ieeexplore.ieee.org/document/9424610/
_version_ 1818572668931145728
author Josy Elsa Varghese
Balachandra Muniyal
author_facet Josy Elsa Varghese
Balachandra Muniyal
author_sort Josy Elsa Varghese
collection DOAJ
description The rapid usage of the Internet for the last few decades has lead to the deployment of high-speed networks in commercial and educational institutions. As network traffic is increasing, security challenges are also increasing in the high-speed network. Although the Intrusion Detection System (IDS) has a significant role in spotting potential attacks, the heavy traffic flow causes severe technical challenges relating to monitoring and detecting the network activities. Moreover, the devastating nature of the Distributed Denial-of-Service (DDoS) attack draws out as a significant cyber-attack regardless of the emergence of Software Defined Network (SDN) architecture. This paper proposes a novel framework to address the performance issues of IDS and the design issues of SDN about DDoS attacks by incorporating intelligence in the data layer using Data Plane Development Kit (DPDK) in the SDN architecture. This novel framework is named as DPDK based DDoS Detection (D3) framework, since DPDK provides fast packet processing and monitoring in the data plane. Moreover, the statistical anomaly detection algorithm implemented in the data plane as Virtual Network Function (VNF) using DPDK offers fast detection of DDoS attacks. The experimental results of the D3 framework guarantee both efficiency and effect of the novel IDS framework. The publicly available CIC DoS datasets also ensure the detection effect of a single statistical anomaly detection algorithm against the DDoS attack.
first_indexed 2024-12-15T00:00:42Z
format Article
id doaj.art-d25fba0ebc1f486b8919d4fa42c59722
institution Directory Open Access Journal
issn 2169-3536
language English
last_indexed 2024-12-15T00:00:42Z
publishDate 2021-01-01
publisher IEEE
record_format Article
series IEEE Access
spelling doaj.art-d25fba0ebc1f486b8919d4fa42c597222022-12-21T22:42:55ZengIEEEIEEE Access2169-35362021-01-019696806969910.1109/ACCESS.2021.30780659424610An Efficient IDS Framework for DDoS Attacks in SDN EnvironmentJosy Elsa Varghese0https://orcid.org/0000-0002-4787-144XBalachandra Muniyal1https://orcid.org/0000-0002-4839-0082Department of Information and Communication Technology, Manipal Institute of Technology, Manipal Academy of Higher Education, Manipal, IndiaDepartment of Information and Communication Technology, Manipal Institute of Technology, Manipal Academy of Higher Education, Manipal, IndiaThe rapid usage of the Internet for the last few decades has lead to the deployment of high-speed networks in commercial and educational institutions. As network traffic is increasing, security challenges are also increasing in the high-speed network. Although the Intrusion Detection System (IDS) has a significant role in spotting potential attacks, the heavy traffic flow causes severe technical challenges relating to monitoring and detecting the network activities. Moreover, the devastating nature of the Distributed Denial-of-Service (DDoS) attack draws out as a significant cyber-attack regardless of the emergence of Software Defined Network (SDN) architecture. This paper proposes a novel framework to address the performance issues of IDS and the design issues of SDN about DDoS attacks by incorporating intelligence in the data layer using Data Plane Development Kit (DPDK) in the SDN architecture. This novel framework is named as DPDK based DDoS Detection (D3) framework, since DPDK provides fast packet processing and monitoring in the data plane. Moreover, the statistical anomaly detection algorithm implemented in the data plane as Virtual Network Function (VNF) using DPDK offers fast detection of DDoS attacks. The experimental results of the D3 framework guarantee both efficiency and effect of the novel IDS framework. The publicly available CIC DoS datasets also ensure the detection effect of a single statistical anomaly detection algorithm against the DDoS attack.https://ieeexplore.ieee.org/document/9424610/Data plane development kit (DPDK)denial of service attack (DoS)DPDK based DoS detection (D3) frameworkhigh-speed networkintrusion detection system (IDS)software defined network (SDN)
spellingShingle Josy Elsa Varghese
Balachandra Muniyal
An Efficient IDS Framework for DDoS Attacks in SDN Environment
IEEE Access
Data plane development kit (DPDK)
denial of service attack (DoS)
DPDK based DoS detection (D3) framework
high-speed network
intrusion detection system (IDS)
software defined network (SDN)
title An Efficient IDS Framework for DDoS Attacks in SDN Environment
title_full An Efficient IDS Framework for DDoS Attacks in SDN Environment
title_fullStr An Efficient IDS Framework for DDoS Attacks in SDN Environment
title_full_unstemmed An Efficient IDS Framework for DDoS Attacks in SDN Environment
title_short An Efficient IDS Framework for DDoS Attacks in SDN Environment
title_sort efficient ids framework for ddos attacks in sdn environment
topic Data plane development kit (DPDK)
denial of service attack (DoS)
DPDK based DoS detection (D3) framework
high-speed network
intrusion detection system (IDS)
software defined network (SDN)
url https://ieeexplore.ieee.org/document/9424610/
work_keys_str_mv AT josyelsavarghese anefficientidsframeworkforddosattacksinsdnenvironment
AT balachandramuniyal anefficientidsframeworkforddosattacksinsdnenvironment
AT josyelsavarghese efficientidsframeworkforddosattacksinsdnenvironment
AT balachandramuniyal efficientidsframeworkforddosattacksinsdnenvironment