Skip to main content

A DDoS Detection and Mitigation System Framework Based on Spark and SDN

  • Conference paper
  • First Online:

Part of the book series: Lecture Notes in Computer Science ((LNISA,volume 10135))

Abstract

Distributed Denial of Service (DDoS) attack is a serious threat to commercial service network. DDoS attack has been studied for years. However, detecting and relieving DDoS attacks are still a problem. Especially, nowadays more and more DDoS attacks produce heavy network traffic, it is hard to response rapidly because that needs high processing performance to process massive traffic data. With big data technology, volumes of network traffic data can be processed much faster. Apache Spark can process a great amount of data in a reasonable time so that DDoS attack can be detected in time. Besides, it is difficult to modify the network configuration in traditional network. With Software-Defined Networking (SDN), a new paradigm in networking, networking can be controlled by programs, which makes modifying the network configuration easier. In this paper, a DDoS detection and mitigation system framework in SDN is introduced, a framework that can control network based on analyzing the network traffic data. Comparing to the traditional defense methods of DDoS attack, the framework can response to DDoS attack by rules automatically.

This is a preview of subscription content, log in via an institution.

Buying options

Chapter
USD   29.95
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
eBook
USD   39.99
Price excludes VAT (USA)
  • Available as EPUB and PDF
  • Read on any device
  • Instant download
  • Own it forever
Softcover Book
USD   54.99
Price excludes VAT (USA)
  • Compact, lightweight edition
  • Dispatched in 3 to 5 business days
  • Free shipping worldwide - see info

Tax calculation will be finalised at checkout

Purchases are for personal use only

Learn about institutional subscriptions

References

  1. Yan, Q., Gong, Q., Deng, F.-A.: Detection of DDoS attacks against wireless SDN controllers based on the fuzzy synthetic evaluation decision-making model. Ad Hoc Sens. Wireless Netw. 33, 275–299 (2016)

    Google Scholar 

  2. DDoS Attack. http://www.webopedia.com/TERM/D/DDoS_attack.html

  3. Middleton, D., Spaulding, A.D.: Q1-2016-state-of-the-internet-security-report. Internet Security and DDoS Attack Report 11-34, Akamai, Q1 2016

    Google Scholar 

  4. Hua Wei: DDoS Defense and Big Data. http://e.huawei.com/de/publications/global/ict_insights/hw_331605/industry%20focus/HW_327000

  5. Apache Hadoop. https://en.wikipedia.org/wiki/Apache_Hadoop

  6. Wiki Apache Spark. https://en.wikipedia.org/wiki/Apache_Spark

  7. Apache Spark. http://spark.apache.org/

  8. Cui, L., Yu, F.R., Yan, Q.: When big data meets software-defined networking: SDN for big data and big data for SDN. IEEE Netw. 30, 58–65 (2016)

    Article  Google Scholar 

  9. Wiki SDN. https://en.wikipedia.org/wiki/Software-defined_networking/

  10. Lee, Y., Lee, Y.: Detecting DDoS attacks with hadoop. In: Proceedings of The ACM CoNEXT Student Workshop, p. 7. ACM (2011)

    Google Scholar 

  11. Lee, Y., Lee, Y.: Toward scalable internet traffic measurement and analysis with hadoop. ACM SIGCOMM Comput. Communi. Rev. 43(1), 5–13 (2013)

    Article  Google Scholar 

  12. Hameed, S., Ali, U.: Efficacy of Live DDoS Detection with Hadoop. In: NOMS 2016 - 2016 IEEE/IFIP Network Operations and Management Symposium, pp. 488–494, April 2016

    Google Scholar 

  13. Yan, Q., Yu, F.R., Gong, Q., Li, J.: Software-defined networking (SDN) and distributed denial of service (DDoS) attacks in cloud computing vironments: A survey, some research issues, and challenges. IEEE Commun. Surv. Tutorials 18(1), 602–622 (2016)

    Article  Google Scholar 

  14. Kreutz, D., Ramos, F.M.V., Verssimo, P.E., Rothenberg, C.E., Azodolmolky, S., Uhlig, S.: Software-defined networking: a comprehensive survey. Proc. IEEE 103, 14–76 (2015)

    Article  Google Scholar 

  15. OpenFlow. https://www.opennetworking.org/sdn-resources/openflow

  16. DPKT. https://pypi.python.org/pypi/dpkt

Download references

Author information

Authors and Affiliations

Authors

Corresponding author

Correspondence to Qiao Yan .

Editor information

Editors and Affiliations

Rights and permissions

Reprints and permissions

Copyright information

© 2017 Springer International Publishing AG

About this paper

Cite this paper

Yan, Q., Huang, W. (2017). A DDoS Detection and Mitigation System Framework Based on Spark and SDN. In: Qiu, M. (eds) Smart Computing and Communication. SmartCom 2016. Lecture Notes in Computer Science(), vol 10135. Springer, Cham. https://doi.org/10.1007/978-3-319-52015-5_35

Download citation

  • DOI: https://doi.org/10.1007/978-3-319-52015-5_35

  • Published:

  • Publisher Name: Springer, Cham

  • Print ISBN: 978-3-319-52014-8

  • Online ISBN: 978-3-319-52015-5

  • eBook Packages: Computer ScienceComputer Science (R0)

Publish with us

Policies and ethics