Denial of Service Detection & Mitigation Scheme using Responsive Autonomic Virtual Networks (RAvN)

Denial of Service Detection & Mitigation Scheme using Responsive Autonomic Virtual Networks (RAvN)
复制标题

DOI:
10.1109/milcom47813.2019.9020809
复制
发表时间:
2019-11
期刊:
MILCOM 2019 - 2019 IEEE Military Communications Conference (MILCOM)
影响因子:
--
通讯作者:
Allen Starke;Zixiang Nie;Morgan Hodges;Corey E. Baker;J. Mcnair
Allen Starke;Zixiang Nie;Morgan Hodges;Corey E. Baker;J. Mcnair
中科院分区:
其他
文献类型:
--
作者:
Allen Starke;Zixiang Nie;Morgan Hodges;Corey E. Baker;J. Mcnair

文献摘要

相似文献

本文提出了一种响应式自主数据驱动的自适应虚拟网络框架(RAVN),它结合了流行的SDN平台开放网络操作系统(ONOS)的自适应可重构特性、流量监测工具T-Shark或sflow-RT提供的网络性能统计信息以及新的和现有的机器学习技术提供的分析和决策技能来检测和缓解异常行为。在本文中,我们致力于开发一种新的检测方案,该方案使用了一种发展的基于质心的聚类技术和网络流量中数据特征的组内方差(C.Intra),并使用适合于网络IP地址的常量变化的多变量高斯分布模型来准确地辅助检测低速率和高速率的拒绝服务(DoS)攻击。我们简要讨论了我们开发决策和执行组件的想法,该组件使用向Onos SDN控制器动态生成自适应策略更新(即异常缓解解决方案)的概念,以更新网络配置和流。此外,我们还对用于检测低率和高率DoS攻击的异常检测方案与常用的无监督机器学习技术KMeans进行了分析。拟议的方案明显优于KMeans。多变量聚类法和组内方差法的准确率分别为80.54%和96.13%,KMeans法的准确率为72.38%。
In this paper we propose a responsive autonomic and data-driven adaptive virtual networking framework (RAvN) that integrates the adaptive reconfigurable features of a popular SDN platform called open networking operating system (ONOS), the network performance statistics provided by traffic monitoring tools such as T-shark or sflow-RT and analytics and decision making skills provided from new and current machine learning techniques to detect and mitigate anomalous behavior. For this paper we focus on the development of novel detection schemes using a developed Centroid-based clustering technique and the Intragroup variance of data features within network traffic (C. Intra), with a multivariate gaussian distribution model fitted to the constant changes in the IP addresses of the network to accurately assist in the detection of low rate and high rate denial of service (DoS) attacks. We briefly discuss our ideas on the development of the decision-making and execution component using the concept of generating adaptive policy updates (i.e. anomalous mitigation solutions) on-the-fly to the ONOS SDN controller for updating network configurations and flows. In addition we provide the analysis on anomaly detection schemes used for detecting low rate and high rate DoS attacks versus a commonly used unsupervised machine learning technique Kmeans. The proposed schemes outperformed Kmeans significantly. The multivariate clustering method and the intragroup variance recorded 80.54% and 96.13% accuracy respectively while Kmeans recorded 72.38% accuracy.