Heterogeneous Hardware-based Network Intrusion Detection System with Multiple Approaches for SDN

被引:9
|
作者
Duc-Minh Ngo [1 ]
Cuong Pham-Quoc [1 ]
Tran Ngoc Thinh [1 ]
机构
[1] Ho Chi Minh City Univ Technol, VNU HCM, Ho Chi Minh City, Vietnam
来源
MOBILE NETWORKS & APPLICATIONS | 2020年 / 25卷 / 03期
关键词
SDN; Heterogeneous platform; Network attacks; Machine learning; NEURAL-NETWORKS;
D O I
10.1007/s11036-019-01437-x
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Software-Defined Networking has became one of the most efficient network architectures to deal with complexity, policy control improvement, and vendor dependencies removal. Besides, with the diversity of network attacks, the SDN architecture faces many security issues that need to be taken into account. In this work, we propose an architecture for SDN-based secured forwarding devices (switches) by extending our previous architecture - HPOFS with multiple security functions including lightweight DDoS mechanisms, signature-based and anomaly-based IDS. We implement our architecture on a heterogeneous system including host processors, GPU, and FPGA boards. To the best of our knowledge, this is the first forwarding device for SDN implemented on a heterogeneous system in the literature. Our system not only is enhanced security but also provides a high-speed switching capacity based on the OpenFlow standard. The implemented design on GTX Geforce 1080 G1 for training phase is 14x faster when compared to CPU Intel Core i7 - 4770, 3.4GHz, 16GB of RAM on the Ubuntu version 14.04. The switching function along with three lightweight DDoS detection/prevention mechanisms provide processing speed at 39.48 Gbps on a NetFPGA-10G board (with a Xilinx xc5vtx240t FPGA device). Especially, our neural network models on the NetFPGA-10G board outperform CPU in processing performance by reaching throughputs at 4.84 Gbps. Moreover, the implemented neural network model achieves 99.01% precision with only 0.02% false positive rate when processing a dataset.
引用
收藏
页码:1178 / 1192
页数:15
相关论文
共 50 条
  • [21] Neural network based intrusion detection system for detecting changes in hardware profile
    Om, Hari
    Sarkar, Tapas K.
    [J]. JOURNAL OF DISCRETE MATHEMATICAL SCIENCES & CRYPTOGRAPHY, 2009, 12 (04): : 451 - 466
  • [22] SDN-Based Network Intrusion Detection as DDoS defense system for Virtualization Environment
    Usman, Saifudin
    Winarno, Idris
    Sudarsono, Amang
    [J]. EMITTER-INTERNATIONAL JOURNAL OF ENGINEERING TECHNOLOGY, 2021, 9 (02) : 252 - 267
  • [23] A hardware-based architecture to support flexible real-time parallel intrusion detection
    Mott, Stephen
    Hart, Samuel
    Montminy, David
    Williams, Paul
    Baldwin, Rusty
    [J]. 2007 IEEE INTERNATIONAL CONFERENCE ON SYSTEM OF SYSTEMS ENGINEERING, VOLS 1 AND 2, 2007, : 614 - 619
  • [24] A Hardware-Based Orientation Detection System Using Dendritic Computation
    Nomura, Masahiro
    Chen, Tianqi
    Tang, Cheng
    Todo, Yuki
    Sun, Rong
    Li, Bin
    Tang, Zheng
    [J]. ELECTRONICS, 2024, 13 (07)
  • [25] Intrusion Detection System for IoT Heterogeneous Perceptual Network
    Zhou, Man
    Han, Lansheng
    Lu, Hongwei
    Fu, Cai
    [J]. MOBILE NETWORKS & APPLICATIONS, 2021, 26 (04): : 1461 - 1474
  • [26] Intrusion Detection System for IoT Heterogeneous Perceptual Network
    Man Zhou
    Lansheng Han
    Hongwei Lu
    Cai Fu
    [J]. Mobile Networks and Applications, 2021, 26 : 1461 - 1474
  • [27] Flexible software-hardware Network Intrusion Detection System
    Proudfoot, Ryan
    Kent, Kenneth
    Aubanel, Eric
    Chen, Nan
    [J]. RSP 2008: 19TH IEEE/IFIP INTERNATIONAL SYMPOSIUM ON RAPID SYSTEM PROTOTYPING, PROCEEDINGS, 2008, : 182 - 188
  • [28] Distributed Hardware-Based Microkernels: Making Heterogeneous OS Functionality A System Primitive
    Agron, Jason
    Andrews, David
    [J]. 2010 18TH IEEE ANNUAL INTERNATIONAL SYMPOSIUM ON FIELD-PROGRAMMABLE CUSTOM COMPUTING MACHINES (FCCM 2010), 2010, : 39 - 46
  • [29] Hardware-based Hash Functions for Network Applications
    Yamaguchi, Fumito
    Nishi, Hiroaki
    [J]. 2013 19TH IEEE INTERNATIONAL CONFERENCE ON NETWORKS (ICON), 2013,
  • [30] Two Hardware-Based Approaches for Deterministic Multiprocessor Replay
    Hower, Derek R.
    Montesinos, Pablo
    Ceze, Luis
    Hill, Mark D.
    Torrellas, Josep
    [J]. COMMUNICATIONS OF THE ACM, 2009, 52 (06) : 93 - 100