Claim Missing Document
Check
Articles

Found 2 Documents
Search
Journal : Indonesian Journal of Electrical Engineering and Computer Science

A deep learning approach to detect DDoS flooding attacks on SDN controller Bahashwan, Abdullah Ahmed; Anbar, Mohammed; Manickam, Selvakumar; Al-Amiedy, Taief Alaa; Hasbullah, Iznan H.
Indonesian Journal of Electrical Engineering and Computer Science Vol 38, No 2: May 2025
Publisher : Institute of Advanced Engineering and Science

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.11591/ijeecs.v38.i2.pp1245-1255

Abstract

Software-defined networking (SDN), integrated into technologies like internet of things (IoT), cloud computing, and big data, is a key component of the fourth industrial revolution. However, its deployment introduces security challenges that can undermine its effectiveness. This highlights the urgent need for security-focused SDN solutions, driving advancements in SDN technology. The absence of inherent security countermeasures in the SDN controller makes it vulnerable to distributed denial of service (DDoS) attacks, which pose a significant and pervasive threat. These attacks specifically target the controller, disrupting services for legitimate users and depleting its resources, including bandwidth, memory, and processing power. This research aims to develop an effective deep learning (DL) approach to detect such attacks, ensuring the availability, integrity, and consistency of SDN network functions. The proposed DL detection approach achieves 98.068% accuracy, 98.085% precision, 98.067% recall, 98.057% F1-score, 1.34% false positive rate (FPR), and 1.713% detection time.
Proposed security mechanism for preventing fake router advertisement attack in IPv6 link-local network Al-Shareeda, Mahmood A.; Manickam, Selvakumar; Saare, Murtaja Ali; Arjuman, Navaneethan C.
Indonesian Journal of Electrical Engineering and Computer Science Vol 29, No 1: January 2023
Publisher : Institute of Advanced Engineering and Science

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.11591/ijeecs.v29.i1.pp518-526

Abstract

The design of router discovery (RD) is a trust mechanism to confirm the legitimacy of the host and router. Fake router advertisement (RA) attacks have been made possible by this RD protocol design defect. Studies show that the standard RD protocol is vulnerable to a fake RA attack where the host will be denied a valid gateway. To cope with this problem, several prevention techniques have been proposed in the past to secure the RD process. Nevertheless, these methods have a significant temporal complexity as well as other flaws, including the bootstrapping issue and hash collision attacks. Thus, the SecMac-secure router discovery (SecMac-SRD) technique, which requires reduced processing time and may thwart fake RA assaults, is proposed in this study as an improved secure RD mechanism. SecMac-SRD is built based on a UMAC hashing algorithm with ElGamal public key distribution cryptosystem that hides the RD message exchange in the IPv6 link-local network. Based on the obtained expected results display that the SecMac-SRD mechanism achieved less processing time compared to the existing secure RD mechanism and can resist fake RA attacks. The outcome of the expected results clearly proves that the SecMac-SRD mechanism effectively copes with the fake RA attacks during the RD process.