Unsupervised online anomaly detection in Software Defined Network environments

被引:10
|
作者
Scaranti, Gustavo Frigo [1 ]
Carvalho, Luiz Fernando [2 ]
Barbon, Sylvio [1 ]
Lloret, Jaime [3 ]
Proenca, Mario Lemes [1 ]
机构
[1] Univ Estadual Londrina, Comp Sci Dept, BR-86057970 Londrina, Parana, Brazil
[2] Fed Univ Technol Parana UTFPR, Comp Engn Dept, BR-86812460 Apucarana, Brazil
[3] Univ Politecn Valencia, Integrated Management Coastal Res Inst, Valencia 46022, Spain
关键词
Anomaly detection; Software Defined Networking (SDN); Stream mining; DenStream; DDoS; Portscan; MITIGATION;
D O I
10.1016/j.eswa.2021.116225
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Software Defined Networking (SDN) simplifies network management and significantly reduces operational costs. SDN removes the control plane from forwarding devices (e.g., routers and switches) and centralizes this plane in a controller, enabling the management of the network forwarding decisions by programming the control plane with a high-level language. However, its centralized architecture may be compromised by flooding attacks, such as Distributed Denial of Service (DDoS) and portscan. Facing this challenge, we propose an Intrusion Detection System (IDS) based on online clustering to detect attacks in an evolving SDN network taking advantage of the entropy of source and destination IP addresses and ports. Our proposal is focused on avoiding the demand for labeling and previous knowledge to provide a practical and accurate method to address real-life online scenarios. Moreover, our proposal paves the way for a comprehensive analysis by projecting the cluster's structure over the feature space, providing insights on intensity, seasonality, and attack type. Our experiments were carried out with the DenStream algorithm in several databases attacked by DDoS and portscan with different intensities, durations, and overlapping patterns. When comparing DenStream performance to Half-Space-Trees, an accurate online one-class classification algorithm for anomaly detection, it was possible to expose the capacity of our unsupervised proposal, overcoming the one-class solution, and reaching f-measure rates above 99.60%.
引用
收藏
页数:13
相关论文
共 50 条
  • [21] Revisiting Traffic Anomaly Detection Using Software Defined Networking
    Mehdi, Syed Akbar
    Khalid, Junaid
    Khayam, Syed Ali
    [J]. RECENT ADVANCES IN INTRUSION DETECTION, 2011, 6961 : 161 - 180
  • [22] Efficient Forwarding Anomaly Detection in Software-Defined Networks
    Li, Qi
    Liu, Yunpeng
    Liu, Zhuotao
    Zhang, Peng
    Pang, Chunhui
    [J]. IEEE TRANSACTIONS ON PARALLEL AND DISTRIBUTED SYSTEMS, 2021, 32 (11) : 2676 - 2690
  • [23] ANOMALY DETECTION IN ATM-GRADE SOFTWARE DEFINED NETWORKS
    Lellek, Philipp
    Leydold, Peter
    Vojnoski, Igor
    Eier, Dieter
    [J]. 2021 INTEGRATED COMMUNICATIONS NAVIGATION AND SURVEILLANCE CONFERENCE (ICNS), 2021,
  • [24] MSCA: An Unsupervised Anomaly Detection System for Network Security in Backbone Network
    Liu, Yating
    Gu, Yuantao
    Shen, Xinyue
    Liao, Qingmin
    Yu, Quan
    [J]. IEEE TRANSACTIONS ON NETWORK SCIENCE AND ENGINEERING, 2023, 10 (01): : 223 - 238
  • [25] Unsupervised anomaly detection for network traffic using artificial immune network
    Yuanquan Shi
    Hong Shen
    [J]. Neural Computing and Applications, 2022, 34 : 13007 - 13027
  • [26] Unsupervised anomaly detection for network traffic using artificial immune network
    Shi, Yuanquan
    Shen, Hong
    [J]. NEURAL COMPUTING & APPLICATIONS, 2022, 34 (15): : 13007 - 13027
  • [27] Unsupervised Anomaly Detection
    Guthrie, David
    Guthrie, Louise
    Allison, Ben
    Wilks, Yorick
    [J]. 20TH INTERNATIONAL JOINT CONFERENCE ON ARTIFICIAL INTELLIGENCE, 2007, : 1624 - 1628
  • [28] An Adaptable and Unsupervised TinyML Anomaly Detection System for Extreme Industrial Environments
    Antonini, Mattia
    Pincheira, Miguel
    Vecchio, Massimo
    Antonelli, Fabio
    [J]. SENSORS, 2023, 23 (04)
  • [29] An Overview of Anomaly Detection for Online Social Network
    Elghanuni, Ramzi H.
    Ali, Musab A. M.
    Swidan, Marwa B.
    [J]. 2019 IEEE 10TH CONTROL AND SYSTEM GRADUATE RESEARCH COLLOQUIUM (ICSGRC), 2019, : 172 - 177
  • [30] Online Anomaly Detection for Virtualized Network Slicing
    Wang Weili
    Chen Qianbin
    Tang Lun
    [J]. JOURNAL OF ELECTRONICS & INFORMATION TECHNOLOGY, 2020, 42 (06) : 1460 - 1467