A survey and classification of the security anomaly detection mechanisms in software defined networks

被引:34
|
作者
Jafarian, Tohid [1 ]
Masdari, Mohammad [1 ]
Ghaffari, Ali [2 ]
Majidzadeh, Kambiz [1 ]
机构
[1] Islamic Azad Univ, Dept Comp Engn, Urmia Branch, Orumiyeh, Iran
[2] Islamic Azad Univ, Dept Comp Engn, Tabriz Branch, Tabriz, Iran
关键词
Sdns; OpenFlow; Anomaly detection; Data plane; Security challenges; Virtual networks; FLOW; MITIGATION; TAXONOMY; SDN;
D O I
10.1007/s10586-020-03184-1
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Software defined network (SDN) decouples the network control and data planes. Despite various advantages of SDNs, they are vulnerable to various security attacks such anomalies, intrusions, and Denial-of-Service (DoS) attacks and so on. On the other hand, any anomaly and intrusion in SDNs can affect many important domains such as banking system and national security. Therefore, the anomaly detection topic is a broad research domain, and to mitigate these security problems, a great deal of research has been conducted in the literature. In this paper, the state-of-the-art schemes applied in detecting and mitigating anomalies in SDNs are explained, categorized, and compared. This paper categorizes the SDN anomaly detection mechanisms into five categories: (1) flow counting scheme, (2) information-based scheme, (3) entropy-based scheme, (4) deep learning, and (5) hybrid scheme. The research gaps and major existing research issues regarding SDN anomaly detection are highlighted. We hope that the analyses, comparisons, and classifications might provide directions for further research.
引用
收藏
页码:1235 / 1253
页数:19
相关论文
共 50 条
  • [41] SADM-SDNC: security anomaly detection and mitigation in software-defined networking using C-support vector classification
    Jafarian, Tohid
    Masdari, Mohammad
    Ghaffari, Ali
    Majidzadeh, Kambiz
    [J]. COMPUTING, 2021, 103 (04) : 641 - 673
  • [42] Attack-Specific Feature Selection for Anomaly Detection in Software-Defined Networks
    Abbas, Nadine
    Nasser, Youssef
    Shehab, Maryam
    Sharafeddine, Sanaa
    [J]. 2021 3RD IEEE MIDDLE EAST AND NORTH AFRICA COMMUNICATIONS CONFERENCE (MENACOMM), 2021, : 142 - 146
  • [43] SADM-SDNC: security anomaly detection and mitigation in software-defined networking using C-support vector classification
    Tohid Jafarian
    Mohammad Masdari
    Ali Ghaffari
    Kambiz Majidzadeh
    [J]. Computing, 2021, 103 : 641 - 673
  • [44] Enhancing Security of Software Defined Mobile Networks
    Liyanage, Madhusanka
    Ahmed, Ijaz
    Okwuibe, Jude
    Ylianttila, Mika
    Kabir, Hammad
    Santos, Jesus Llorente
    Kantola, Raimo
    Lopez Perez, Oscar
    Uriarte Itzazelaia, Mikel
    De Oca, Edgardo Monies
    [J]. IEEE ACCESS, 2017, 5 : 9422 - 9438
  • [45] Towards security automation in Software Defined Networks
    Yungaicela-Naula, Noe M.
    Vargas-Rosales, Cesar
    Arturo Perez-Diaz, Jesus
    Zareei, Mahdi
    [J]. COMPUTER COMMUNICATIONS, 2022, 183 : 64 - 82
  • [46] The (In)Security of Topology Discovery in Software Defined Networks
    Alharbi, Talal
    Portmann, Marius
    Pakzad, Farzaneh
    [J]. 40TH ANNUAL IEEE CONFERENCE ON LOCAL COMPUTER NETWORKS (LCN 2015), 2015, : 502 - 505
  • [47] Software-Defined Mobile Networks Security
    Chen, Min
    Qian, Yongfeng
    Mao, Shiwen
    Tang, Wan
    Yang, Ximin
    [J]. MOBILE NETWORKS & APPLICATIONS, 2016, 21 (05): : 729 - 743
  • [48] Security for Future Software Defined Mobile Networks
    Liyanage, Madhusanka
    Ahmad, Ijaz
    Ylianttila, Mika
    Santos, Jesus Llorente
    Kantola, Raimo
    Lopez Perez, Oscar
    Uriarte Itzazelaia, Mikel
    de Oca, Edgardo Montes
    Valtierra, Asier
    Jimenez, Carlos
    [J]. 2015 9TH INTERNATIONAL CONFERENCE ON NEXT GENERATION MOBILE APPLICATIONS, SERVICES AND TECHNOLOGIES (NGMAST 2015), 2015, : 256 - 264
  • [49] A Security Services Platform for Software Defined Networks
    Tatlicioglu, Sinan
    Civanlar, Seyhan
    Gorkemli, Burak
    Lokman, Erhan
    Balci, A. Metin
    Eliacik, C. Bora
    [J]. 2016 IEEE CONFERENCE ON NETWORK FUNCTION VIRTUALIZATION AND SOFTWARE DEFINED NETWORKS (NFV-SDN), 2016, : 39 - 43
  • [50] Security Threats and Countermeasures in Software Defined Networks
    Ahmed, Adnan
    Manzoor, Adnan
    Halepoto, Imtiaz Ali
    Abbas, Fizza
    Rajput, Ubaidullah
    [J]. INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2018, 18 (04): : 69 - 74