Detecting Saturation Attacks in SDN via Machine Learning

Detecting Saturation Attacks in SDN via Machine Learning
复制标题

DOI:
10.1109/cccs.2019.8888049
复制
发表时间:
2019-10
期刊:
2019 4th International Conference on Computing, Communications and Security (ICCCS)
影响因子:
--
通讯作者:
Samer Y. Khamaiseh;Edoardo Serra;Zhiyuan Li;Dianxiang Xu
Samer Y. Khamaiseh;Edoardo Serra;Zhiyuan Li;Dianxiang Xu
中科院分区:
其他
文献类型:
--
作者:
Samer Y. Khamaiseh;Edoardo Serra;Zhiyuan Li;Dianxiang Xu

文献摘要

被引文献

相似文献

软件定义网络(SDN)是一种新的网络模式,它通过将控制平面与数据平面分开来促进网络管理。研究表明,当OpenFlow通道被饱和攻击淹没时,SDN可能会经历较高的丢包率和较长的报文转发延迟。现有的方法主要是通过对网络流量的周期性分析来检测由TCP-SYN洪泛引起的饱和攻击。然而,有两个问题。首先,以前的方法无法检测到其他类型的饱和攻击,特别是未知类型的饱和攻击。其次,它们依赖于网络流量的预定时间窗口,因此无法确定流量数据的哪个时间窗口适合于有效的攻击检测。针对这些问题,本文首先研究了OpenFlow流量的不同时间窗口对三种分类算法:支持向量机、朴素贝叶斯分类器和K-近邻分类器检测性能的影响。我们已经在从物理和模拟SDN环境生成的OpenFlow流量数据集上构建并分析了总共150个模型。实验结果表明,OpenFlow流量的时间间隔选择对检测性能有很大影响--较大的时间窗口可能会导致检测性能下降。此外,通过应用OpenFlow流量的适当时间窗口,我们能够在检测未知攻击时获得合理的准确性。
Software Defined Networking (SDN) is a new network paradigm that facilitates network management by separating the control plane from the data plane. Studies have shown that an SDN may experience a high packet loss rate and a long delay in forwarding messages when the OpenFlow channel is overwhelmed by a saturation attack. The existing approaches have focused on the detection of saturation attacks caused by TCP-SYN flooding through periodic analysis of network traffic. However, there are two issues. First, previous approaches are incapable of detecting other types, especially unknown types, of saturation attacks. Second, they rely on predetermined time-window of network traffic and thus are unable to determine what time window of traffic data would be appropriate for effective attack detection. To tackle these problems, this paper first investigates the impact of different time-windows of OpenFlow traffic on the detection performance of three classification algorithms: the Support Vector Machine (SVM), the Naïve Bayes (NB) classifier, and the K-Nearest Neighbors (K-NN) classifier. We have built and analyzed a total of 150 models on OpenFlow traffic datasets generated from both physical and simulated SDN environments. The experiment results show that the chosen time-interval of OpenFlow traffic heavily influences the detection performance – larger time-windows may result in decreased detection performance. In addition, we were able to achieve reasonable accuracy on detection of unknown attacks by applying proper time-windows of OpenFlow traffic.