Support Vector Machine (SVM) based Detection for Volumetric Bandwidth Distributed Denial of Service (DVB-DDOS) attack within gigabit Passive Optical Network

Authors

  • Sumayya Bibi Faculty of Electrical Engineering, Universiti Teknologi Malaysia
  • Nadiatulhuda Zulkifli Faculty of Electrical Engineering, Universiti Teknologi Malaysia
  • Ghazanfar Ali Safdar University of Bedfordshire
  • Sajid Iqbal King Faisal University

DOI:

https://doi.org/10.22441/sinergi.2025.1.017

Keywords:

Attack detection system, Dynamic Bandwidth Assignment, Machine learning, Passive optical Network, SVM

Abstract

The dynamic bandwidth allocation (DBA) algorithm is highly impactful in improving the network performance of gigabit passive optical networks (GPON). Network security is an important component of today’s networks to combat security attacks, including GPON. However, the literature contains reports highlighting its vulnerability to specific attacks, thereby raising concerns. In this work, we argue that the impact of a volumetric bandwidth distributed denial of service (DVB-DDOS) attack can be mitigated by improving the dynamic bandwidth assignment (DBA) scheme, which is used in PON to manage the US bandwidth at the optical line terminal (OLT). Thus, this study uses a support vector machine (SVM), a machine learning approach, to learn the optical network unit (ONU) traffic demand patterns and presents a hybrid security-aware DBA (HSA-DBA) scheme that is capable of distinguishing malicious ONUs from normal ONUs. In this article, we consider the deployment of the HSA-DBA scheme in OMNET++ to acquire the monitoring data samples used to train the ML technique for the effective classification of ONUs. The simulation findings revealed a mean upstream delay improvement of up to 63% due to the security feature offered by the mechanism. Besides, significant reductions for the upstream delay performance recorded at 63% TCONT2, 65% TCONT3, and 95% TCONT4 and for frame loss rate reduction for normal ONU traffic, respectively, were observed in comparison to the non-secure DBA mechanism. This research provides a significant stride towards secure GPONs, ensuring reliable defense mechanisms are in place, which paves the way for more resilient future broadband network infrastructures.

Downloads

Download data is not yet available.

Downloads

Additional Files

Published

2025-01-04

How to Cite

[1]
S. Bibi, N. Zulkifli, G. A. Safdar, and S. Iqbal, “Support Vector Machine (SVM) based Detection for Volumetric Bandwidth Distributed Denial of Service (DVB-DDOS) attack within gigabit Passive Optical Network”, Sinergi, vol. 29, no. 1, pp. 185–196, Jan. 2025.

Issue

Section

Articles

Most read articles by the same author(s)