Distributed denial-of-service attack mitigation in network functions virtualization-based 5G networks using management and orchestration

No Thumbnail Available

Date

2021

Journal Title

Journal ISSN

Volume Title

Publisher

Wiley

Research Projects

Organizational Units

Organizational Unit
Department of Electrical & Electronics Engineering
Department of Electrical and Electronics Engineering (EE) offers solid graduate education and research program. Our Department is known for its student-centered and practice-oriented education. We are devoted to provide an exceptional educational experience to our students and prepare them for the highest personal and professional accomplishments. The advanced teaching and research laboratories are designed to educate the future workforce and meet the challenges of current technologies. The faculty's research activities are high voltage, electrical machinery, power systems, signal and image processing and photonics. Our students have exciting opportunities to participate in our department's research projects as well as in various activities sponsored by TUBİTAK, and other professional societies. European Remote Radio Laboratory project, which provides internet-access to our laboratories, has been accomplished under the leadership of our department with contributions from several European institutions.

Journal Issue

Abstract

The fifth generation (5G) technology is expected to allow connectivity to billions of devices, known as Internet of Things (IoT). However, IoT devices will inevitably be the main target of various cyberattack types. The most common one is known as distributed denial-of-service (DDoS) attack. In order to mitigate such attacks, network functions virtualization (NFV) has a great potential to provide the benefit of elasticity and low-cost solutions for protecting 5G networks. In this context, this study proposes a new mechanism developed to mitigate DDoS attacks in 5G NFV networks. The proposed mechanism utilizes intrusion prevention system's (IPS) virtual machines (VMs) to intercept the queries. Based on the volume of DDoS traffic, IPS's VMs are dynamically deployed by means of management and orchestration (MANO) in order to balance the load. To evaluate the effectiveness of the mechanism, experiments are conducted in a real 5G NFV environment built by using 5G NFV environment tools. To our best knowledge, this is the first time that NFV-based mechanism is experimentally tested in a real 5G NFV environment for mitigating DDoS attacks in 5G networks. The experimental results verify that the proposed mechanism can mitigate DDoS attacks effectively.

Description

Kara, Ali/0000-0002-9739-7619; Maiga, Bamoye/0000-0003-4219-6630

Keywords

5G security, DDoS, MANO, NFV, OpenStack

Turkish CoHE Thesis Center URL

Citation

1

WoS Q

Q3

Scopus Q

Q2

Source

Volume

34

Issue

9

Start Page

End Page

Collections