Revisiting Traffic Anomaly Detection Using Software Defined Networking
نویسندگان
چکیده
Despite their exponential growth, home and small office/home office networks continue to be poorly managed. Consequently, security of hosts in most home networks is easily compromised and these hosts are in turn used for largescale malicious activities without the home users’ knowledge. We argue that the advent of Software Defined Networking (SDN) provides a unique opportunity to effectively detect and contain network security problems in home and home office networks. We show how four prominent traffic anomaly detection algorithms can be implemented in an SDN context using Openflow compliant switches and NOX as a controller. Our experiments indicate that these algorithms are significantly more accurate in identifying malicious activities in the home networks as compared to the ISP. Furthermore, the efficiency analysis of our SDN implementations on a programmable home network router indicates that the anomaly detectors can operate at line rates without introducing any performance penalties for the home network traffic.
منابع مشابه
Efficient Anomaly Detection Using Adaptive Monitoring in SDN
Network monitoring and measurement is the key task in today’s networking scenarios due to increasing low-level intrusions. With the increase in utilization of resources and wider network bandwidth gateway for intruders also enlarges. Hence to detect the anomalies entered by the intruders inside our network a better anomaly detection mechanism must need to be implemented. Also software-defined n...
متن کاملAdaptive Query Rate for Anomaly Detection with SDN
In traditional approach, extracting important features for the application to analyze the anomaly detection problem, introduce significant overhead on the way of switch handling. Furthermore, high volumes of network traffic introduce notable issues that affect the performance and anomaly detection accuracy. Taking advantage of centralized control plane of Software Defined Networking (SDN), the ...
متن کاملA Defense Mechanism of Random Routing Mutation in SDN
Focused on network reconnaissance, eavesdropping, and DoS attacks caused by static routing policies, this paper designs a random routing mutation architecture based on the OpenFlow protocol, which takes advantages of the global network view and centralized control in a software-defined network. An entropy matrix of network traffic characteristics is constructed by using volume measurements and ...
متن کاملA transparent and scalable anomaly-based DoS detection method
Intrusions and intrusive behaviour can be aimed at different parts of the system, ranging from lower-level network attacks intended to disrupt the flow of data in general, to higher-level attacks targeted against specific applications or services. Due to the constant growth of network traffic and the need to inspect the traffic thoroughly, intrusion detection and prevention are becoming increas...
متن کاملReal-Time Timing Channel Detection in a Software-Defined Networking Virtual Environment
Despite extensive research, timing channels (TCs) are still known as a principal category of threats that aim to leak and transmit information by perturbing the timing or ordering of events. Existing TC detection approaches use either signature-based approaches to detect known TCs or anomalybased approach by modeling the legitimate network traffic in order to detect unknown TCs. Unfortunately, ...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2011