Unsupervised online anomaly detection in Software Defined Network environments

Unsupervised online anomaly detection in Software Defined Network environments
复制标题

DOI:
10.1016/j.eswa.2021.116225
复制
发表时间:
2021-12-13
影响因子:
8.5
通讯作者:
Proenca, Mario Lemes
Proenca, Mario Lemes
中科院分区:
计算机科学1区
文献类型:
--
作者:
Scaranti, Gustavo Frigo;Carvalho, Luiz Fernando;Proenca, Mario Lemes

文献摘要

被引文献

相似文献

软件定义网络(SDN)简化了网络管理并显著降低了运营成本。SDN从转发设备移除控制平面(例如,路由器和交换机),并将该平面集中在控制器中,从而通过用高级语言对控制平面进行编程来实现对网络转发决策的管理。然而,其集中式架构可能会受到洪水攻击的影响,例如分布式拒绝服务(DDoS)和端口扫描。面对这一挑战,我们提出了一种基于在线聚类的入侵检测系统(IDS),利用源和目的IP地址和端口的熵来检测不断发展的SDN网络中的攻击。我们的建议重点是避免对标签和先前知识的需求,以提供一种实用而准确的方法来解决现实生活中的在线场景。此外,我们的建议通过将集群的结构投影到特征空间上,为全面分析铺平了道路,提供了对强度,季节性和攻击类型的见解。我们的实验进行了DenStream算法在几个数据库攻击的DDoS和端口扫描具有不同的强度,持续时间和重叠模式。当将DenStream的性能与半空间树(一种用于异常检测的准确在线单类分类算法)进行比较时,可以暴露我们的无监督建议的能力,克服单类解决方案,并达到99.60%以上的f-测量率。
Software Defined Networking (SDN) simplifies network management and significantly reduces operational costs. SDN removes the control plane from forwarding devices (e.g., routers and switches) and centralizes this plane in a controller, enabling the management of the network forwarding decisions by programming the control plane with a high-level language. However, its centralized architecture may be compromised by flooding attacks, such as Distributed Denial of Service (DDoS) and portscan. Facing this challenge, we propose an Intrusion Detection System (IDS) based on online clustering to detect attacks in an evolving SDN network taking advantage of the entropy of source and destination IP addresses and ports. Our proposal is focused on avoiding the demand for labeling and previous knowledge to provide a practical and accurate method to address real-life online scenarios. Moreover, our proposal paves the way for a comprehensive analysis by projecting the cluster's structure over the feature space, providing insights on intensity, seasonality, and attack type. Our experiments were carried out with the DenStream algorithm in several databases attacked by DDoS and portscan with different intensities, durations, and overlapping patterns. When comparing DenStream performance to Half-Space-Trees, an accurate online one-class classification algorithm for anomaly detection, it was possible to expose the capacity of our unsupervised proposal, overcoming the one-class solution, and reaching f-measure rates above 99.60%.