Towards Analysis of the Performance of IDSs in Software-Defined Networks

被引:1
|
作者
Niknami, Nadia [1 ]
Inkrott, Emily [2 ]
Wu, Jie [1 ]
机构
[1] Temple Univ, Dept Comp & Informat Sci, Philadelphia, PA 19122 USA
[2] Gonzaga Univ, Dept Comp Sci, Spokane, WA 99258 USA
关键词
Denial-of-service; detection rate; intrusion detection system; network traffic; software-defined network;
D O I
10.1109/MASS56207.2022.00124
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
As a promising technique for the design of 5G wireless networks, software-defined networks (SDNs) have been proposed. However, SDNs are vulnerable to most of the attacks that traditional networks are vulnerable to. Various techniques have been developed and designed to help in the detection as well as the prevention of various attacks. An intrusion detection system (IDS) is one of the common techniques used to detect malicious activity in a network. Intrusion detection systems have strengths and weaknesses when it comes to detecting intrusions. It becomes a challenging task for IDS to process any mixture of traffic that results in packet drop and delay. In this study, we scrutinized two open-source IDS, including Snort IDS and Zeek IDS, to assess the IDS performance in terms of various parameters such as detection rate, dropping rate, and latency. The method of detection was one of the main differences between Snort and Zeek. Zeek IDS uses an anomaly-based detection method as opposed to Snort IDS, which uses a signature-based detection method. Differences between them had an impact on the way network traffic was handled. Such a thought analysis is expected to be of great value in selection and further enhancement of IDS in SDN.
引用
收藏
页码:787 / 793
页数:7
相关论文
共 50 条
  • [21] Towards Filling the Gap of Routing Changes in Software-Defined Networks
    Malik, Ali
    Aziz, Benjamin
    Adda, Mo
    [J]. PROCEEDINGS OF THE FUTURE TECHNOLOGIES CONFERENCE (FTC) 2018, VOL 2, 2019, 881 : 682 - 693
  • [22] Towards Virtualization of Software-Defined Networks: A Journey in Three Acts
    Blenk, Andreas
    Kellerer, Wolfgang
    [J]. 2019 IFIP/IEEE SYMPOSIUM ON INTEGRATED NETWORK AND SERVICE MANAGEMENT (IM), 2019, : 677 - 682
  • [23] Towards distributed emergency flow prioritization in software-defined networks
    Moeyersons, Jerico
    Farkiani, Behrooz
    Wauters, Tim
    Volckaert, Bruno
    De Turck, Filip
    [J]. INTERNATIONAL JOURNAL OF NETWORK MANAGEMENT, 2021, 31 (01)
  • [24] Towards an Efficient DDoS Detection Scheme for Software-Defined Networks
    Lima, N. A. S.
    Fernandez, M. P.
    [J]. IEEE LATIN AMERICA TRANSACTIONS, 2018, 16 (08) : 2296 - 2301
  • [25] Performance Analysis of Software-Defined Networking (SDN)
    Gelberger, Alexander
    Yemini, Niv
    Giladi, Ran
    [J]. 2013 IEEE 21ST INTERNATIONAL SYMPOSIUM ON MODELING, ANALYSIS & SIMULATION OF COMPUTER AND TELECOMMUNICATION SYSTEMS (MASCOTS 2013), 2013, : 389 - 393
  • [26] Languages for Software-Defined Networks
    Foster, Nate
    Guha, Arjun
    Reitblatt, Mark
    Story, Alec
    Freedman, Michael J.
    Katta, Naga Praveen
    Monsanto, Christopher
    Reich, Joshua
    Rexford, Jennifer
    Schlesinger, Cole
    Walker, David
    Harrison, Major Robert
    [J]. IEEE COMMUNICATIONS MAGAZINE, 2013, 51 (02) : 128 - 134
  • [27] On the Security of Software-Defined Networks
    Prasad, Abhinandan S.
    Koll, David
    Fu, Xiaoming
    [J]. 2015 FOURTH EUROPEAN WORKSHOP ON SOFTWARE DEFINED NETWORKS - EWSDN 2015, 2015, : 105 - 106
  • [28] Software-Defined Access Networks
    Elbers, Joerg-Peter
    Grobe, Klaus
    Magee, Anthony
    [J]. 2014 EUROPEAN CONFERENCE ON OPTICAL COMMUNICATION (ECOC), 2014,
  • [29] Abstractions for Software-Defined Networks
    Casado, Martin
    Foster, Nate
    Guha, Arjun
    [J]. COMMUNICATIONS OF THE ACM, 2014, 57 (10) : 86 - 95
  • [30] On the Fingerprinting of Software-Defined Networks
    Cui, Heng
    Karame, Ghassan O.
    Klaedtke, Felix
    Bifulco, Roberto
    [J]. IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2016, 11 (10) : 2160 - 2173