Voting-based intrusion detection framework for securing software-defined networks

被引:20
|
作者
Swami, Rochak [1 ]
Dave, Mayank [1 ]
Ranga, Virender [1 ]
机构
[1] Natl Inst Technol, Dept Comp Engn, Kurukshetra, Haryana, India
来源
关键词
DDoS; IDS; software-defined networking; voting; SYSTEMS STATISTICAL-ANALYSIS; DHCP STARVATION ATTACK; CIDDS-001; DATASET; ANOMALY DETECTION; DDOS DEFENSE; SDN;
D O I
10.1002/cpe.5927
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Software-defined networking (SDN) is an emerging paradigm in enterprise networks because of its flexible and cost-effective nature. By decoupling control and data plane, SDN can provide various defense solutions for securing futuristic networks. However, the architectural design and characteristics of SDN attract several severe attacks. Distributed denial of service (DDoS) is considered as a major destructive cyber attack that makes the services of controller unavailable for its legitimate users. In this research article, an intrusion detection framework is proposed to detect DDoS attacks against SDN. The proposed framework relies on voting-based ensemble model for the attack detection. Ensemble model is a combination of multiple machine learning classifiers for prediction of final results. In this research article, we propose and analyze three ensemble models named as Voting-CMN, Voting-RKM, and Voting-CKM particularly to benchmarking datasets such as UNSW-NB15, CICIDS2017, and NSL-KDD, respectively. For validation of the proposed models, a cross-validation technique is used with the prediction algorithms. The effectiveness of proposed models is evaluated in terms of prominent metrics (accuracy, precision, recall, and F-measure). Experimental results indicate that the proposed models achieve better performance in terms of accuracy as compared with other existing models.
引用
收藏
页数:16
相关论文
共 50 条
  • [1] A kangaroo-based intrusion detection system on software-defined networks
    Yazdinejadna, Abbas
    Parizi, Reza M.
    Dehghantanha, Ali
    Khan, Mohammad S.
    [J]. COMPUTER NETWORKS, 2021, 184
  • [2] An Intrusion Detection System Based on Genetic Algorithm for Software-Defined Networks
    Zhao, Xuejian
    Su, Huiying
    Sun, Zhixin
    [J]. MATHEMATICS, 2022, 10 (21)
  • [3] On Securing Healthcare with Software-Defined Networks
    Gupta, Sahil
    Acharya, H. B.
    Kwon, Minseok
    [J]. IEEE CONFERENCE ON COMPUTER COMMUNICATIONS WORKSHOPS (IEEE INFOCOM 2019 WKSHPS), 2019, : 354 - 359
  • [4] Towards an efficient anomaly-based intrusion detection for software-defined networks
    Latah, Majd
    Toker, Levent
    [J]. IET NETWORKS, 2018, 7 (06) : 453 - 459
  • [5] Suspicious traffic sampling for intrusion detection in software-defined networks
    Ha, Taejin
    Kim, Sunghwan
    An, Namwon
    Narantuya, Jargalsaikhan
    Jeong, Chiwook
    Kim, JongWon
    Lim, Hyuk
    [J]. COMPUTER NETWORKS, 2016, 109 : 172 - 182
  • [6] Securing Data Planes in Software-Defined Networks
    Chao, Tzu-Wei
    Ke, Yu-Ming
    Chen, Bo-Han
    Chen, Jhu-Lin
    Hsieh, Chen Jung
    Lee, Shao-Chuan
    Hsiao, Hsu-Chun
    [J]. 2016 IEEE NETSOFT CONFERENCE AND WORKSHOPS (NETSOFT), 2016, : 465 - 470
  • [7] A Framework for Policy Inconsistency Detection in Software-Defined Networks
    Lee, Seungsoo
    Woo, Seungwon
    Kim, Jinwoo
    Nam, Jaehyun
    Yegneswaran, Vinod
    Porras, Phillip
    Shin, Seungwon
    [J]. IEEE-ACM TRANSACTIONS ON NETWORKING, 2022, 30 (03) : 1410 - 1423
  • [8] An Efficient Intrusion Detection Framework in Software-Defined Networking for Cybersecurity Applications
    Alshammri, Ghalib H.
    Samha, Amani K.
    Hemdan, Ezz El-Din
    Amoon, Mohammed
    El-Shafai, Walid
    [J]. CMC-COMPUTERS MATERIALS & CONTINUA, 2022, 72 (02): : 3529 - 3548
  • [9] A Review of Artificial Intelligence Based Intrusion Detection for Software-Defined Wireless Sensor Networks
    Umba, S. Masengo Wa
    Abu-Mahfouz, Adnan M.
    Ramotsoela, T. D.
    Hancke, Gerhard P.
    [J]. 2019 IEEE 28TH INTERNATIONAL SYMPOSIUM ON INDUSTRIAL ELECTRONICS (ISIE), 2019, : 1277 - 1282
  • [10] Flexible Network-based Intrusion Detection and Prevention System on Software-defined Networks
    An Le
    Phuong Dinh
    Hoa Le
    Ngoc Cuong Tran
    [J]. 2015 INTERNATIONAL CONFERENCE ON ADVANCED COMPUTING AND APPLICATIONS (ACOMP), 2015, : 106 - 111