Unsupervised online anomaly detection in Software Defined Network environments

被引:10
|
作者
Scaranti, Gustavo Frigo [1 ]
Carvalho, Luiz Fernando [2 ]
Barbon, Sylvio [1 ]
Lloret, Jaime [3 ]
Proenca, Mario Lemes [1 ]
机构
[1] Univ Estadual Londrina, Comp Sci Dept, BR-86057970 Londrina, Parana, Brazil
[2] Fed Univ Technol Parana UTFPR, Comp Engn Dept, BR-86812460 Apucarana, Brazil
[3] Univ Politecn Valencia, Integrated Management Coastal Res Inst, Valencia 46022, Spain
关键词
Anomaly detection; Software Defined Networking (SDN); Stream mining; DenStream; DDoS; Portscan; MITIGATION;
D O I
10.1016/j.eswa.2021.116225
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Software Defined Networking (SDN) simplifies network management and significantly reduces operational costs. SDN removes the control plane from forwarding devices (e.g., routers and switches) and centralizes this plane in a controller, enabling the management of the network forwarding decisions by programming the control plane with a high-level language. However, its centralized architecture may be compromised by flooding attacks, such as Distributed Denial of Service (DDoS) and portscan. Facing this challenge, we propose an Intrusion Detection System (IDS) based on online clustering to detect attacks in an evolving SDN network taking advantage of the entropy of source and destination IP addresses and ports. Our proposal is focused on avoiding the demand for labeling and previous knowledge to provide a practical and accurate method to address real-life online scenarios. Moreover, our proposal paves the way for a comprehensive analysis by projecting the cluster's structure over the feature space, providing insights on intensity, seasonality, and attack type. Our experiments were carried out with the DenStream algorithm in several databases attacked by DDoS and portscan with different intensities, durations, and overlapping patterns. When comparing DenStream performance to Half-Space-Trees, an accurate online one-class classification algorithm for anomaly detection, it was possible to expose the capacity of our unsupervised proposal, overcoming the one-class solution, and reaching f-measure rates above 99.60%.
引用
收藏
页数:13
相关论文
共 50 条
  • [41] Unsupervised network traffic anomaly detection based on score iterations
    Ping, Guolou
    Zeng, Tingyu
    Ye, Xiaojun
    [J]. Qinghua Daxue Xuebao/Journal of Tsinghua University, 2022, 62 (05): : 819 - 824
  • [42] TOWARDS AN UNSUPERVISED METHOD FOR NETWORK ANOMALY DETECTION IN LARGE DATASETS
    Bhuyan, Monowar Hussain
    Bhattacharyya, Dhruba K.
    Kalita, Jugal K.
    [J]. COMPUTING AND INFORMATICS, 2014, 33 (01) : 1 - 34
  • [43] Industrial Anomaly Detection: A Comparison of Unsupervised Neural Network Architectures
    Siegel, Barry
    [J]. IEEE SENSORS LETTERS, 2020, 4 (08)
  • [44] Unsupervised Machine Learning for Anomaly Detection in Synchrophasor Network Traffic
    Donner, Phillip
    Leger, Aaron St.
    Blaine, Raymond
    [J]. 2019 51ST NORTH AMERICAN POWER SYMPOSIUM (NAPS), 2019,
  • [45] A graph encoder-decoder network for unsupervised anomaly detection
    Mesgaran, Mahsa
    Ben Hamza, A.
    [J]. NEURAL COMPUTING & APPLICATIONS, 2023, 35 (32): : 23521 - 23535
  • [46] Applying fuzzy data mining to network unsupervised anomaly detection
    Xiang, G
    Min, W
    Zhao, RC
    [J]. INTERNATIONAL SYMPOSIUM ON COMMUNICATIONS AND INFORMATION TECHNOLOGIES 2005, VOLS 1 AND 2, PROCEEDINGS, 2005, : 1249 - 1253
  • [47] DEFIO: A Software Defined Storage Network Architecture in HPC Environments
    Shi, Wei
    Lv, Gaofeng
    Sun, Zhigang
    Gong, Zhenghu
    [J]. 2015 IEEE 17TH INTERNATIONAL CONFERENCE ON HIGH PERFORMANCE COMPUTING AND COMMUNICATIONS, 2015 IEEE 7TH INTERNATIONAL SYMPOSIUM ON CYBERSPACE SAFETY AND SECURITY, AND 2015 IEEE 12TH INTERNATIONAL CONFERENCE ON EMBEDDED SOFTWARE AND SYSTEMS (ICESS), 2015, : 1703 - 1706
  • [48] Validating User Flows to Protect Software Defined Network Environments
    Abdulqadder, Ihsan H.
    Zou, Deqing
    Aziz, Israa T.
    Yuan, Bin
    [J]. SECURITY AND COMMUNICATION NETWORKS, 2018,
  • [49] Study and Evaluation of Unsupervised Algorithms Used in Network Anomaly Detection
    Dromard, Juliette
    Owezarski, Philippe
    [J]. PROCEEDINGS OF THE FUTURE TECHNOLOGIES CONFERENCE (FTC) 2019, VOL 2, 2020, 1070 : 397 - 416
  • [50] MTAD: Multiobjective Transformer Network for Unsupervised Multisensor Anomaly Detection
    Belay, Mohammed Ayalew
    Rasheed, Adil
    Rossi, Pierluigi Salvo
    [J]. IEEE SENSORS JOURNAL, 2024, 24 (12) : 20254 - 20265