A two-phase detection method against APT attack on flow table management in SDN

被引:1
|
作者
He, Xinfeng [1 ,2 ]
Sun, Shuchao [1 ,2 ]
机构
[1] Hebei Univ, Sch Cyber Secur & Comp, Baoding 071002, Peoples R China
[2] Key Lab High Trusted Informat Syst Hebei Prov, Baoding 071002, Peoples R China
来源
JOURNAL OF SUPERCOMPUTING | 2023年 / 79卷 / 14期
关键词
Software-defined networking; Flow table management; APT attacks; B-P neural network;
D O I
10.1007/s11227-023-05281-5
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Long-term occupation of flow table can occur in the management mechanism of software-defined networking (SDN), which is a prerequisite for APT attacks. The task of detecting such APT attacks in existent research is mainly undertaken by the controller, which results in high computation overhead. To address this problem, a two-phase detection method for APT attacks on flow table management (TMAF) is proposed in this paper. Firstly, the suspicious flow entries are pre-detected in the SDN switch according to the periodicity of the packet. Secondly, the five-dimensional features of suspicious flow entries are selected according to the characteristics of packets in load and frequency, and then the B-P neural network on the controller for further analysis. Experiments show that TMAF reduces the controller's load and improves the detection efficiency and accuracy compared to existing works. Additionally, the potential risk of APT attacks can be reduced to a certain extent.
引用
收藏
页码:15415 / 15434
页数:20
相关论文
共 50 条
  • [41] A CGAN-based DDoS Attack Detection Method in SDN
    Liu
    Luo
    Jiang
    Wang
    Li
    Jia
    IWCMC 2021: 2021 17TH INTERNATIONAL WIRELESS COMMUNICATIONS & MOBILE COMPUTING CONFERENCE (IWCMC), 2021, : 1030 - 1034
  • [42] Application of Adjacent Data Dependency Method in Two-phase Flow
    Fan, Chunling
    Cui, Jianjun
    Bai, Jie
    2017 CHINESE AUTOMATION CONGRESS (CAC), 2017, : 4462 - 4467
  • [43] Interface transport scheme of a two-phase flow by the method of characteristics
    Haddad, Mireille
    Hecht, Frederic
    Sayah, Toni
    INTERNATIONAL JOURNAL FOR NUMERICAL METHODS IN FLUIDS, 2017, 83 (06) : 513 - 543
  • [44] A Schur Complement Method for Compressible Two-Phase Flow Models
    Dao, Thu-Huyen
    Ndjinga, Michael
    Magoules, Frederic
    DOMAIN DECOMPOSITION METHODS IN SCIENCE AND ENGINEERING XXI, 2014, 98 : 759 - 768
  • [45] An improved IMPES method for two-phase flow in porous media
    Chen, ZX
    Huan, GR
    Li, BY
    TRANSPORT IN POROUS MEDIA, 2004, 54 (03) : 361 - 376
  • [46] The multiscale perturbation method for two-phase reservoir flow problems
    Rocha, Franciane F.
    Mankad, Het
    Sousa, Fabricio S.
    Pereira, Felipe
    APPLIED MATHEMATICS AND COMPUTATION, 2022, 421
  • [47] A Lagrangian vortex method for two-phase particulate flow simulation
    Gharakhani, A.
    FEDSM 2007: PROCEEDINGS OF THE 5TH JOINT AMSE/JSME FLUIDS ENGINEERING SUMMER CONFERENCE VOL 1, PTS A AND B, 2007, : 55 - 61
  • [48] Soft sensoring method for concentration measurement of two-phase flow
    Wang, B.L.
    Huang, Z.Y.
    Chen, G.
    Li, H.Q.
    Zhejiang Daxue Xuebao (Gongxue Ban)/Journal of Zhejiang University (Engineering Science Edition, 2001, 35 (01):
  • [49] An Improved IMPES Method for Two-Phase Flow in Porous Media
    Zhangxin Chen
    Guanren Huan
    Baoyan Li
    Transport in Porous Media, 2004, 54 : 361 - 376
  • [50] Method of experimental evaluation velocity of particles in two-phase flow
    Ruzova, T.A.
    Tolstopyat, A.P.
    Fleyer, L.A.
    Naukovyi Visnyk Natsionalnoho Hirnychoho Universytetu, 2012, 3 : 107 - 113