Unsupervised online anomaly detection in Software Defined Network environments

被引:10
|
作者
Scaranti, Gustavo Frigo [1 ]
Carvalho, Luiz Fernando [2 ]
Barbon, Sylvio [1 ]
Lloret, Jaime [3 ]
Proenca, Mario Lemes [1 ]
机构
[1] Univ Estadual Londrina, Comp Sci Dept, BR-86057970 Londrina, Parana, Brazil
[2] Fed Univ Technol Parana UTFPR, Comp Engn Dept, BR-86812460 Apucarana, Brazil
[3] Univ Politecn Valencia, Integrated Management Coastal Res Inst, Valencia 46022, Spain
关键词
Anomaly detection; Software Defined Networking (SDN); Stream mining; DenStream; DDoS; Portscan; MITIGATION;
D O I
10.1016/j.eswa.2021.116225
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Software Defined Networking (SDN) simplifies network management and significantly reduces operational costs. SDN removes the control plane from forwarding devices (e.g., routers and switches) and centralizes this plane in a controller, enabling the management of the network forwarding decisions by programming the control plane with a high-level language. However, its centralized architecture may be compromised by flooding attacks, such as Distributed Denial of Service (DDoS) and portscan. Facing this challenge, we propose an Intrusion Detection System (IDS) based on online clustering to detect attacks in an evolving SDN network taking advantage of the entropy of source and destination IP addresses and ports. Our proposal is focused on avoiding the demand for labeling and previous knowledge to provide a practical and accurate method to address real-life online scenarios. Moreover, our proposal paves the way for a comprehensive analysis by projecting the cluster's structure over the feature space, providing insights on intensity, seasonality, and attack type. Our experiments were carried out with the DenStream algorithm in several databases attacked by DDoS and portscan with different intensities, durations, and overlapping patterns. When comparing DenStream performance to Half-Space-Trees, an accurate online one-class classification algorithm for anomaly detection, it was possible to expose the capacity of our unsupervised proposal, overcoming the one-class solution, and reaching f-measure rates above 99.60%.
引用
收藏
页数:13
相关论文
共 50 条
  • [1] Online and Scalable Unsupervised Network Anomaly Detection Method
    Dromard, Juliette
    Roudiere, Gilles
    Owezarski, Philippe
    [J]. IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2017, 14 (01): : 34 - 47
  • [2] A Detection Method for Anomaly Flow in Software Defined Network
    Peng, Huijun
    Sun, Zhe
    Zhao, Xuejian
    Tan, Shuhua
    Sun, Zhixin
    [J]. IEEE ACCESS, 2018, 6 : 27809 - 27817
  • [3] Network-Wide Forwarding Anomaly Detection and Localization in Software Defined Networks
    Zhang, Peng
    Zhang, Fangzheng
    Xu, Shimin
    Yang, Zuoru
    Li, Hao
    Li, Qi
    Wang, Huanzhao
    Shen, Chao
    Hu, Chengchen
    [J]. IEEE-ACM TRANSACTIONS ON NETWORKING, 2021, 29 (01) : 332 - 345
  • [4] Generative Adversarial Network Models for Anomaly Detection in Software-Defined Networks
    Zacaron, Alexandro Marcelo
    Lent, Daniel Matheus Brandao
    da Silva Ruffo, Vitor Gabriel
    Carvalho, Luiz Fernando
    Proenca Jr, Mario Lemes
    [J]. JOURNAL OF NETWORK AND SYSTEMS MANAGEMENT, 2024, 32 (04)
  • [5] Effective Online Software Anomaly Detection
    Chen, Yizhen
    Ying, Ming
    Liu, Daren
    Alim, Adil
    Chen, Feng
    Chen, Mei-Hwa
    [J]. PROCEEDINGS OF THE 26TH ACM SIGSOFT INTERNATIONAL SYMPOSIUM ON SOFTWARE TESTING AND ANALYSIS (ISSTA'17), 2017, : 136 - 146
  • [6] An Improved Software Defined Network Detection Algorithm for Real-Time Detection and Anomaly Identification of Network Traffic
    Zhang, Ke
    [J]. International Journal of Network Security, 2023, 25 (05) : 758 - 763
  • [7] Online-compatible unsupervised nonresonant anomaly detection
    Mikuni, Vinicius
    Nachman, Benjamin
    Shih, David
    [J]. PHYSICAL REVIEW D, 2022, 105 (05)
  • [8] An Effective Unsupervised Network Anomaly Detection Method
    Bhuyan, Monowar H.
    Bhattacharyya, D. K.
    Kalita, J. K.
    [J]. PROCEEDINGS OF THE 2012 INTERNATIONAL CONFERENCE ON ADVANCES IN COMPUTING, COMMUNICATIONS AND INFORMATICS (ICACCI'12), 2012, : 533 - 539
  • [9] SDN-PANDA: Software-Defined Network Platform for ANomaly Detection Applications
    Granby, Brian R.
    Askwith, Bob
    Marnerides, Angelos K.
    [J]. 2015 IEEE 23RD INTERNATIONAL CONFERENCE ON NETWORK PROTOCOLS (ICNP), 2015, : 463 - 466
  • [10] Software Defined Machine Learning Based Anomaly Detection in Fog Based IoT Network
    Shafi, Qaisar
    Qaisar, Saad
    Basit, Abdul
    [J]. COMPUTATIONAL SCIENCE AND ITS APPLICATIONS, ICCSA 2019, PT IV, 2019, 11622 : 611 - 621