Wavelet against random forest for anomaly mitigation in software-defined networking

被引:9
|
作者
Zerbini, Cinara Brenda [1 ]
Carvalho, Luiz Fernando [1 ]
Abrao, Taufik [2 ]
Proenca Jr, Mario Lemes [1 ]
机构
[1] Univ Estadual Londrina, Comp Sci Dept, BR-86057970 Londrina, Brazil
[2] Univ Estadual Londrina, Dept Elect Engn, BR-86057970 Londrina, Brazil
关键词
Software-defined networking; Anomaly detection; Wavelet; Random forest; TRANSFORM; SECURITY; SYSTEM; DECOMPOSITION; FRAMEWORK; INTERNET; SDN;
D O I
10.1016/j.asoc.2019.02.046
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Security and availability of computer networks remain critical issues even with the constant evolution of communication technologies. In this core, traffic anomaly detection mechanisms need to be flexible to detect the growing spectrum of anomalies that may hinder proper network operation. In this paper, we argue that Software-defined Networking (SDN) provides a suitable environment for the design and implementation of more robust and comprehensive anomaly detection approaches. Aiming towards automated management to detect and prevent potential problems, we present an anomaly identification mechanism based on Discrete Wavelet Transform (DWT) and compare it with another detection model based on Random Forest. These methods generate a normal traffic profile, which is compared with actual real network traffic to recognize abnormal events. After a threat is detected, mitigation measures are activated so that the harmful effects of the malicious event are contained. We assess the effectiveness of the proposed anomaly detection methods and mitigation schemes using Distributed Denial of Service (DDoS) and port scan attacks. Our results confirm the effectiveness of both methods as well as the mitigation routines. In particular, the correspondence between the detection rates confirms that both methods enhance the detection of anomalous behavior by maintaining a satisfactory false-alarm rate. (C) 2019 Elsevier B.V. All rights reserved.
引用
收藏
页码:138 / 153
页数:16
相关论文
共 50 条
  • [1] An ecosystem for anomaly detection and mitigation in software-defined networking
    Carvalho, Luiz Fernando
    Abrao, Taufik
    Mendes, Leonardo de Souza
    Proenca, Mario Lemes, Jr.
    [J]. EXPERT SYSTEMS WITH APPLICATIONS, 2018, 104 : 121 - 133
  • [2] A Software-defined Networking-based Detection and Mitigation Approach against KRACK
    Li, Yi
    Serrano, Marcos
    Chin, Tommy
    Xiong, Kaiqi
    Lin, Jing
    [J]. PROCEEDINGS OF THE 16TH INTERNATIONAL JOINT CONFERENCE ON E-BUSINESS AND TELECOMMUNICATIONS, VOL 2: SECRYPT, 2019, : 244 - 251
  • [3] Software-Defined Networking
    Kirkpatrick, Keith
    [J]. COMMUNICATIONS OF THE ACM, 2013, 56 (09) : 16 - 19
  • [4] Software-defined networking
    Greene, Kate
    [J]. Technology Review, 2009, 112 (02)
  • [5] Software-Defined Networking
    Zhili Sun
    Jiandong Li
    Kun Yang
    [J]. ZTE Communications, 2014, 12 (02) : 1 - 2
  • [6] HTTP DDoS flooding attack mitigation in software-defined networking
    Park, Sungho
    Kim, Youngjun
    Choi, Hyungoo
    Kyung, Yeunwoong
    Park, Jinwoo
    [J]. IEICE Transactions on Information and Systems, 2021, E104D (09) : 1496 - 1499
  • [7] HTTP DDoS Flooding Attack Mitigation in Software-Defined Networking
    Park, Sungho
    Kim, Youngjun
    Choi, Hyungoo
    Kyung, Yeunwoong
    Park, Jinwoo
    [J]. IEICE TRANSACTIONS ON INFORMATION AND SYSTEMS, 2021, E104D (09): : 1496 - 1499
  • [8] Proactive Mitigation to Table-Overflow in Software-Defined Networking
    Xu, Jianfeng
    Wang, Liming
    Song, Chen
    Xu, Zhen
    [J]. 2018 IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATIONS (ISCC), 2018, : 724 - 730
  • [9] Using Software-Defined Networking for Ransomware Mitigation: The Case of CryptoWall
    Cabaj, Krzysztof
    Mazurczyk, Wojciech
    [J]. IEEE NETWORK, 2016, 30 (06): : 14 - 20
  • [10] EFFICIENT ANOMALY DETECTION AND MITIGATION IN SOFTWARE DEFINED NETWORKING ENVIRONMENT
    Sathya, R.
    Thangarajan, R.
    [J]. 2015 2ND INTERNATIONAL CONFERENCE ON ELECTRONICS AND COMMUNICATION SYSTEMS (ICECS), 2015, : 479 - 484