A two-phase detection method against APT attack on flow table management in SDN

被引:1
|
作者
He, Xinfeng [1 ,2 ]
Sun, Shuchao [1 ,2 ]
机构
[1] Hebei Univ, Sch Cyber Secur & Comp, Baoding 071002, Peoples R China
[2] Key Lab High Trusted Informat Syst Hebei Prov, Baoding 071002, Peoples R China
来源
JOURNAL OF SUPERCOMPUTING | 2023年 / 79卷 / 14期
关键词
Software-defined networking; Flow table management; APT attacks; B-P neural network;
D O I
10.1007/s11227-023-05281-5
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Long-term occupation of flow table can occur in the management mechanism of software-defined networking (SDN), which is a prerequisite for APT attacks. The task of detecting such APT attacks in existent research is mainly undertaken by the controller, which results in high computation overhead. To address this problem, a two-phase detection method for APT attacks on flow table management (TMAF) is proposed in this paper. Firstly, the suspicious flow entries are pre-detected in the SDN switch according to the periodicity of the packet. Secondly, the five-dimensional features of suspicious flow entries are selected according to the characteristics of packets in load and frequency, and then the B-P neural network on the controller for further analysis. Experiments show that TMAF reduces the controller's load and improves the detection efficiency and accuracy compared to existing works. Additionally, the potential risk of APT attacks can be reduced to a certain extent.
引用
收藏
页码:15415 / 15434
页数:20
相关论文
共 50 条
  • [31] An APT Event Extraction Method Based on BERT-BiGRU-CRF for APT Attack Detection
    Xiang, Ga
    Shi, Chen
    Zhang, Yangsen
    ELECTRONICS, 2023, 12 (15)
  • [32] A Feasible Method to combat against DDoS Attack in SDN Network
    Nhu-Ngoc Dao
    Park, Junho
    Park, Minho
    Cho, Sungrae
    2015 INTERNATIONAL CONFERENCE ON INFORMATION NETWORKING (ICOIN), 2015, : 309 - 311
  • [33] The method of virtual power applied to two-phase flow with phase change
    Coutris, N
    Delhaye, JM
    CHEMICAL ENGINEERING COMMUNICATIONS, 1996, 141 : 145 - 153
  • [34] Method of virtual power applied to two-phase flow with phase change
    Cent d'Etudes Nucleaires de Grenoble, Grenoble, France
    Chem Eng Commun, (145-153):
  • [35] Study on the gas-liquid two-phase flow two-phase flow characteristics of carbon dioxide removal by membrane method
    Li Yanchao
    Hao Zhiwu
    Zeng Xianping
    Li Fangqin
    Ren Jianxing
    RENEWABLE AND SUSTAINABLE ENERGY, PTS 1-7, 2012, 347-353 : 1797 - 1800
  • [36] A New Method for Ultrasound Detection of Interfacial Position in Gas-Liquid Two-Phase Flow
    Coutinho, Fabio Rizental
    Ofuchi, Cesar Yutaka
    Ramos de Arruda, Lucia Valeria
    Neves, Flvio, Jr.
    Morales, Rigoberto E. M.
    SENSORS, 2014, 14 (05): : 9093 - 9116
  • [37] Two-phase cryogenic flow meters Part II - How to realize the two-phase pressure drop method
    Filippov, Yu. P.
    Panferov, K. S.
    CRYOGENICS, 2011, 51 (11-12) : 640 - 645
  • [38] Development of a two-phase flow solver with drift-flux model based on OpenFOAM: Validation against single/two-phase and boiling flow
    Wu, Wenqiang
    Huang, Tao
    Du, Peng
    Zhang, Dalin
    Zhou, Lei
    Wang, Bo
    Deng, Jian
    Qiu, Zhifang
    Tian, Wenxi
    Qiu, Suizheng
    Su, Guanghui
    ANNALS OF NUCLEAR ENERGY, 2025, 213
  • [39] A two-phase flow interface capturing finite element method
    Devals, C.
    Heniche, M.
    Bertrand, F.
    Tanguy, P. A.
    Hayes, R. E.
    INTERNATIONAL JOURNAL FOR NUMERICAL METHODS IN FLUIDS, 2007, 53 (05) : 735 - 751
  • [40] Method of Distributions for Two-Phase Flow in Heterogeneous Porous Media
    Yang, Hyung Jun
    Tchelepi, Hamdi A.
    Tartakovsky, Daniel M.
    WATER RESOURCES RESEARCH, 2022, 58 (12)