Deployment of Intrusion Prevention System Based on Software Defined Networking

被引:0
|
作者
Zhang, Lei [1 ]
Shou, Guochu [1 ]
Hu, Yihong [1 ]
Guo, Zhigang [1 ]
机构
[1] Beijing Univ Posts & Telecommun, Beijing Lab Network Syst Architecture & Convergen, Sch Informat & Commun Engn, Beijing 100876, Peoples R China
关键词
SDN/OpenFlow; network security; Intrusion Prevention System(IPS); load balancing;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The development of the mobile Internet brought about by the thriving mobile intelligent terminals has made it possible to access to the Internet anytime and anywhere. While people enjoy the convenience, they also suffer from a series of security threats caused by cyber-attacks. IPS brings reliability and security in a network system and is regarded as one of the most popular security devices. However, the conventional IPS deployment often has some limitations, and the deployment and maintenance costs are expensive, the utilization rate is low. In order to solve these issues, an SDN-based IPS deployment is presented in this paper, which supports a unified scheduling of security applications in the whole network and load balancing among IPSs. In addition, this paper builds a test-bed and shows evaluation results. As the results, It is confirmed that the proposed scheme can achieve a shorter time for ping after the first ping and that with the load balancing, the network latency is significantly reduced.
引用
收藏
页码:26 / 31
页数:6
相关论文
共 50 条
  • [1] Intrusion Detection and Prevention in Software Defined Networking
    Goyal, Abhilash
    Gupta, Divyansh
    [J]. 2018 IEEE INTERNATIONAL CONFERENCE ON ADVANCED NETWORKS AND TELECOMMUNICATIONS SYSTEMS (ANTS), 2018,
  • [2] SDNIPS: Enabling Software-Defined Networking Based Intrusion Prevention System in Clouds
    Xing, Tianyi
    Xiong, Zhengyang
    Huang, Dijiang
    Medhi, Deep
    [J]. 2014 10TH INTERNATIONAL CONFERENCE ON NETWORK AND SERVICE MANAGEMENT (CNSM), 2014, : 308 - 311
  • [3] Risk based intrusion detection system in software defined networking
    Chetouane, Ameni
    Karoui, Kamel
    [J]. CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2024, 36 (09):
  • [4] An adaptive multistage intrusion detection and prevention system in software defined networking environment
    Maheswaran, N.
    Bose, S.
    Natarajan, Buvaneswari
    [J]. AUTOMATIKA, 2024, 65 (04) : 1364 - 1378
  • [5] HMM-based Intrusion Detection System for Software Defined Networking
    Hurley, Trae
    Perdomo, Jorge E.
    Perez-Pons, Alexander
    [J]. 2016 15TH IEEE INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND APPLICATIONS (ICMLA 2016), 2016, : 617 - 621
  • [6] Cloud Based Intrusion Detection and Prevention System for Industrial Control Systems Using Software Defined Networking
    Brugman, Jonathon
    Khan, Mohammed
    Kasera, Sneha
    Parvania, Masood
    [J]. 2019 RESILIENCE WEEK (RWS), 2019, : 98 - 104
  • [7] A multi-layered intrusion detection system for software defined networking
    Bour, Hamideh
    Abolhasan, Mehran
    Jafarizadeh, Saber
    Lipman, Justin
    Makhdoom, Imran
    [J]. COMPUTERS & ELECTRICAL ENGINEERING, 2022, 101
  • [8] Reduction of the Delays Within an Intrusion Detection System (IDS) Based on Software Defined Networking (SDN)
    Fausto, Alessandro
    Gaggero, Giovanni
    Patrone, Fabio
    Marchese, Mario
    [J]. IEEE ACCESS, 2022, 10 : 109850 - 109862
  • [9] A Framework of Blockchain-Based Collaborative Intrusion Detection in Software Defined Networking
    Li, Wenjuan
    Tan, Jiao
    Wang, Yu
    [J]. NETWORK AND SYSTEM SECURITY, NSS 2020, 2020, 12570 : 261 - 276
  • [10] WedgeTail: An Intrusion Prevention System for the Data Plane of Software Defined Networks
    Shaghaghi, Arash
    Kaafar, Mohamed Ali
    Jha, Sanjay
    [J]. PROCEEDINGS OF THE 2017 ACM ASIA CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY (ASIA CCS'17), 2017, : 849 - 861