A DDoS attack detection method based on conditional entropy and decision tree in SDN
CSTR:
Author:
Affiliation:

College of Computer Science, Chongqing University, Chongqing 400044, P. R. China

Clc Number:

TP393

Fund Project:

Supported by National Natural Science Foundation of China (61309013).

  • Article
  • |
  • Figures
  • |
  • Metrics
  • |
  • Reference
  • |
  • Related
  • |
  • Cited by
  • |
  • Materials
  • |
  • Comments
    Abstract:

    Software defined network (SDN), as a novel network architecture, introduces significant flexibility through the ideas including separation between forwarding and controlling and centralized control. It also facilitates the global awareness of the network status. Distributed denial of service (DDoS) is a typical attack method. This paper focuses on the problem DDoS attack detection in SDN and proposes a DDoS attack detection method based on conditional entropy and decision tree. The proposed method used conditional entropy to evaluate the current network status. It analyzed the characteristics of DDoS attacks in SDN and extracted six key features for traffic detection. The C4.5 decision tree algorithm was utilized to classify network traffic and achieved DDoS attack detection in SDN. Experimental results show that the method presented in this paper exhibits superior detection precision and recall to other research methods. Additionally, it can significantly reduce the detection time.

    Reference
    Related
    Cited by
Get Citation

傅友,邹东升.SDN中基于条件熵和决策树的DDoS攻击检测方法[J].重庆大学学报,2023,46(7):1~8

Copy
Related Videos

Share
Article Metrics
  • Abstract:
  • PDF:
  • HTML:
  • Cited by:
History
  • Received:March 12,2022
  • Revised:
  • Adopted:
  • Online: August 02,2023
  • Published:
Article QR Code