Adaptive Detection Method for Packet-In Message Injection Attack in SDN

  • Xinyu Zhan
  • , Mingsong Chen
  • , Shui Yu
  • , Yue Zhang*
  • *Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

9 Scopus citations

Abstract

Packet-In message injection attack is severe in Software Defined Network (SDN), which will cause a single point of failure of the centralized controller and the crash of the entire network. Nowadays, there are many detection methods for it, including entropy detection and so on. We propose an adaptive detection method to proactively defend against this attack. We establish a Poisson probability distribution detection model to find the attack and use the flow table filter to mitigate it. We also use the EWMA method to update the expectation value of the model to adapt the actual network conditions. Our method has no need to send additional packets to request the switch information. The experiment results show that there is 92% true positive rate in case of attack with random destination IP packets injected, and true positive rate is 98.2% under the attack with random source IP packets injected.

Original languageEnglish
Title of host publicationAlgorithms and Architectures for Parallel Processing - 19th International Conference, ICA3PP 2019, Proceedings
EditorsSheng Wen, Albert Zomaya, Laurence T. Yang
PublisherSpringer
Pages482-495
Number of pages14
ISBN (Print)9783030389604
DOIs
StatePublished - 2020
Event19th International Conference on Algorithms and Architectures for Parallel Processing, ICA3PP 2019 - Melbourne, Australia
Duration: 9 Dec 201911 Dec 2019

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume11945 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference19th International Conference on Algorithms and Architectures for Parallel Processing, ICA3PP 2019
Country/TerritoryAustralia
CityMelbourne
Period9/12/1911/12/19

Keywords

  • Adaptive detection
  • Controller security
  • Packet-In message injection attack
  • Software-Defined Network

Fingerprint

Dive into the research topics of 'Adaptive Detection Method for Packet-In Message Injection Attack in SDN'. Together they form a unique fingerprint.

Cite this