Heterogeneous Hardware-based Network Intrusion Detection System with Multiple Approaches for SDN

被引:9
|
作者
Duc-Minh Ngo [1 ]
Cuong Pham-Quoc [1 ]
Tran Ngoc Thinh [1 ]
机构
[1] Ho Chi Minh City Univ Technol, VNU HCM, Ho Chi Minh City, Vietnam
来源
MOBILE NETWORKS & APPLICATIONS | 2020年 / 25卷 / 03期
关键词
SDN; Heterogeneous platform; Network attacks; Machine learning; NEURAL-NETWORKS;
D O I
10.1007/s11036-019-01437-x
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Software-Defined Networking has became one of the most efficient network architectures to deal with complexity, policy control improvement, and vendor dependencies removal. Besides, with the diversity of network attacks, the SDN architecture faces many security issues that need to be taken into account. In this work, we propose an architecture for SDN-based secured forwarding devices (switches) by extending our previous architecture - HPOFS with multiple security functions including lightweight DDoS mechanisms, signature-based and anomaly-based IDS. We implement our architecture on a heterogeneous system including host processors, GPU, and FPGA boards. To the best of our knowledge, this is the first forwarding device for SDN implemented on a heterogeneous system in the literature. Our system not only is enhanced security but also provides a high-speed switching capacity based on the OpenFlow standard. The implemented design on GTX Geforce 1080 G1 for training phase is 14x faster when compared to CPU Intel Core i7 - 4770, 3.4GHz, 16GB of RAM on the Ubuntu version 14.04. The switching function along with three lightweight DDoS detection/prevention mechanisms provide processing speed at 39.48 Gbps on a NetFPGA-10G board (with a Xilinx xc5vtx240t FPGA device). Especially, our neural network models on the NetFPGA-10G board outperform CPU in processing performance by reaching throughputs at 4.84 Gbps. Moreover, the implemented neural network model achieves 99.01% precision with only 0.02% false positive rate when processing a dataset.
引用
收藏
页码:1178 / 1192
页数:15
相关论文
共 50 条
  • [1] Heterogeneous Hardware-based Network Intrusion Detection System with Multiple Approaches for SDN
    Duc-Minh Ngo
    Cuong Pham-Quoc
    Tran Ngoc Thinh
    [J]. Mobile Networks and Applications, 2020, 25 : 1178 - 1192
  • [2] A New Curriculum for Hardware-Based Network Intrusion Detection
    Lo, Dan
    Wang, Andy
    North, Sarah
    North, Max
    [J]. PROCEEDINGS OF THE 49TH ANNUAL ASSOCIATION FOR COMPUTING MACHINERY SOUTHEAST CONFERENCE (ACMSE '11), 2011, : 318 - 319
  • [3] HH-NIDS: Heterogeneous Hardware-Based Network Intrusion Detection Framework for IoT Security
    Ngo, Duc-Minh
    Lightbody, Dominic
    Temko, Andriy
    Pham-Quoc, Cuong
    Tran, Ngoc-Thinh
    Murphy, Colin C. C.
    Popovici, Emanuel
    [J]. FUTURE INTERNET, 2023, 15 (01):
  • [4] UNITE: Uniform hardware-based network intrusion deTection engine
    Yusuf, S.
    Luk, W.
    Szeto, M. K. N.
    Osborne, W.
    [J]. RECONFIGURABLE COMPUTING: ARCHITECTURES AND APPLICATIONS, 2006, 3985 : 389 - 400
  • [5] HPCgnature: a hardware-based application-level intrusion detection system
    Musavi, Seyyedeh Atefeh
    Hashemi, Mahmoud Reza
    [J]. IET INFORMATION SECURITY, 2019, 13 (01) : 19 - 26
  • [6] Survey on SDN based network intrusion detection system using machine learning approaches
    Nasrin Sultana
    Naveen Chilamkurti
    Wei Peng
    Rabei Alhadad
    [J]. Peer-to-Peer Networking and Applications, 2019, 12 : 493 - 501
  • [7] Survey on SDN based network intrusion detection system using machine learning approaches
    Sultana, Nasrin
    Chilamkurti, Naveen
    Peng, Wei
    Alhadad, Rabei
    [J]. PEER-TO-PEER NETWORKING AND APPLICATIONS, 2019, 12 (02) : 493 - 501
  • [8] Applying hardware-based machine learning to signature-based network intrusion detection
    Payer, Garrett
    McCormick, Chris
    Harang, Richard
    [J]. CYBER SENSING 2014, 2014, 9097
  • [9] Applying hardware-based machine learning to signature-based network intrusion detection
    Payer, Garrett
    McCormick, Chris
    Harang, Richard
    [J]. MACHINE INTELLIGENCE AND BIO-INSPIRED COMPUTATION: THEORY AND APPLICATIONS VIII, 2014, 9119
  • [10] A Survey on Hardware-Based Malware Detection Approaches
    Chenet, Cristiano Pegoraro
    Savino, Alessandro
    Di Carlo, Stefano
    [J]. IEEE ACCESS, 2024, 12 : 54115 - 54128