Enhancing Load Balancing by Intrusion Detection System Chain on SDN Data Plane

Enhancing Load Balancing by Intrusion Detection System Chain on SDN Data Plane
复制标题

DOI:
10.1109/cns56114.2022.9947270
复制
发表时间:
2022-10
期刊:
2022 IEEE Conference on Communications and Network Security (CNS)
影响因子:
--
通讯作者:
Nadia Niknami;Jie Wu
Nadia Niknami;Jie Wu
中科院分区:
其他
文献类型:
--
作者:
Nadia Niknami;Jie Wu

文献摘要

相似文献

软件定义网络(SDN)允许我们轻松动态地控制网络流量。入侵检测系统(IDS)是控制器的应用之一。IDS在分析大量流量时可能会过载。建议在网络中使用多个IDS实例以提高处理能力。SDN集中控制便于在数据平面上部署多个IDS。本文提出了一种部署多个IDS链的方法,帮助控制器提高检测率。通过以平衡的方式对流进行分组并将每个组分配给一个IDS链,可以减少传输延迟。在这项研究中,我们制定了一个优化问题,以最大限度地减少使用修改后的版本的K-means和分配IDS链分组流的成本。我们实现了我们的方法上的测试床和基于跟踪的模拟。在不同的流量情况下,我们提出的方法可以满足不同的测量,如检测率和丢弃率,并只增加了一个IDS方案的延迟量很小。
The software-defined network (SDN) allows us to control network flows easily and dynamically. Intrusion detection systems (IDS) are among the controller's applications. The IDS can become overloaded when analyzing a large amount of traffic. Multiple instances of IDSs are recommended across a network to increase processing power. SDN centralized control facilitates the deployment of multiple IDSs on the data plane. This paper proposes a method to deploy some IDS chains, helping the controller increase the detection rate. By grouping flows in a balanced manner and assigning each group to one IDS chain, transmission delay can be reduced. In this study, we formulate an optimization problem to minimize the cost of grouping flows using a modified version of K-means and assigning an IDS chain. We implement our method on a test bed and a trace-based simulation. In various traffic scenarios, our proposed method can satisfy different measurements, such as detection rate and dropping rate, and only increases the delay by a small amount over one IDS scheme.