Implementation of ICMP flood detection and mitigation system based on software-defined network and sFlow-RT
Rikie Kartadie, Adi Kusjani, Rangga Warsito, Yudhi Kusnanto, Lucia Nugraheni Harnaningrum
Abstract
This study evaluates internet control message protocol (ICMP) flood detection and mitigation in software-defined networks (SDN) using an SDN architecture with sFlow-RT for real-time traffic monitoring. OpenFlow switches and sFlow agents detect malicious patterns, following the prepare, plan, design, implement, operate, optimize (PPDIOO) methodology. Unlike prior approaches, this system leverages SDN programmability and sFlow-RT’s real-time analytics to reduce ICMP packets from 311,130.2 to 99 and latency by 80%, outperforming traditional methods in speed and responsiveness. It ensures network availability, with practical benefits for large-scale networks like internet service providers (ISPs). However, sFlow sampling rates may affect accuracy in high-speed networks, and a single OpenDaylight (ODL) controller limits generalizability. Future work should test alternative controllers and extend to other DDoS types like user datagram protocol (UDP) floods in diverse topologies.
Keywords
internet control message protocol flood; network security; openflow; software-defined networks; sflow-rt;
DOI:
http://doi.org/10.12928/telkomnika.v23i3.26304
Refbacks
There are currently no refbacks.
This work is licensed under a
Creative Commons Attribution-ShareAlike 4.0 International License .
TELKOMNIKA Telecommunication, Computing, Electronics and Control ISSN: 1693-6930, e-ISSN: 2302-9293Universitas Ahmad Dahlan , 4th Campus Jl. Ringroad Selatan, Kragilan, Tamanan, Banguntapan, Bantul, Yogyakarta, Indonesia 55191 Phone: +62 (274) 563515, 511830, 379418, 371120 Fax: +62 274 564604
<div class="statcounter"><a title="Web Analytics" href="http://statcounter.com/" target="_blank"><img class="statcounter" src="//c.statcounter.com/10241713/0/0b6069be/0/" alt="Web Analytics"></a></div> View TELKOMNIKA Stats