Skip to main content
Article

Mitigating DNS query-based DDoS attacks with machine learning on software-defined networking

Muhammad Ejaz AhmedCollege of Software, Sungkyunkwan University (SKKU), Suwon, KoreaHyoungshick KimCollege of Software, Sungkyunkwan University (SKKU), Suwon, KoreaMoosung ParkAgency for Defense Development, Korea
2017en
ABI

Abstract

Securing Internet of Things is a challenge because of its multiple points of vulnerability. In particular, Distributed Denial of Service (DDoS) attacks on IoT devices pose a major security challenge to be addressed. In this paper, we propose a DNS query-based DDoS attack mitigation system using Software-Defined Networking (SDN) to block the network traffic for DDoS attacks. With some features provided by SDN, we can analyze traffic patterns and filter suspicious network flows out. To show the feasibility of the proposed system, we particularly implemented a prototype with Dirichlet process mixture model to distinguish benign traffic from malicious traffic and conducted experiments with the dataset collected from real network traces. We demonstrate the effectiveness of the proposed method by both simulations and experiment data obtained from the real network traffic traces.

Identifiers

Citations and references

Cited by 20 references