Detection and Mitigation of SYN Flooding Attacks through SYN/ACK Packets and Black/White Lists

Sensors (Basel). 2023 Apr 7;23(8):3817. doi: 10.3390/s23083817.

Abstract

Software-defined networking (SDN) is a new network architecture that provides programmable networks, more efficient network management, and centralized control than traditional networks. The TCP SYN flooding attack is one of the most aggressive network attacks that can seriously degrade network performance. This paper proposes detection and mitigation modules against SYN flooding attacks in SDN. We combine those modules, which have evolved from the cuckoo hashing method and innovative whitelist, to get better performance compared to current methods Our approach reduces the traffic through the switch and improves detection accuracy, also the required register size is reduced by half for the same accuracy.

Keywords: SYN flooding; cybersecurity; programmable data plane; software-defined network (SDN).