A Novel Machine Learning Framework for Advanced Attack Detection using SDN

被引:20
|
作者
Abou El Houda, Zakaria [1 ,3 ]
Hafid, Abdelhakim Senhaji [1 ]
Khoukhi, Lyes [2 ]
机构
[1] Univ Montreal, Dept Comp Sci & Operat Res, NRL, Montreal, PQ, Canada
[2] Normandie Univ, ENSICAEN, GREYC CNRS, Paris, France
[3] Univ Technol Troyes, Troyes, France
关键词
Machine Learning; Intrusion Detection System; Isolation Forest; SDN;
D O I
10.1109/GLOBECOM46510.2021.9685643
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Recently, software defined networks (SDN) has emerged as novel technology that leverages network programmability to facilitate network management. SDN provides a global view of the network, through a logically centralized component, called SDN controller, to strengthen network security. SDN separates the control plane from the data plane, which allows for a more control over the network and brings new capabilities to cope with the new emerging security threats (i.e., zero-day attacks). Existing attack detection schemes are facing obstacles due to high false positive rates, low detection performances, and high computational costs. To address these issues, we propose a multi-module Machine Learning (ML) framework that combines unsupervised ML techniques with a scalable feature collection and selection scheme to effectively/timely detect network security threats in the context of SDN. In particular, our proposed framework consists of: (1) a data flow collection module (DFC) to gather the features of network data in a scalable and efficient way using sFlow protocol; (2) an Information gain Feature Selection (IGF) module to select the most informative/relevant features to reduce training and testing time complexity; and (3) a novel unsupervised ML module that uses a novel outlier detection scheme, called Isolation Forest (ML-IF), to effectively/timely detect network security threats in SDN. The experimental results using the well-known public network security dataset UNSW-NB15, show that our proposed framework outperforms state-of-the-art contributions in terms of accuracy and detection rate while significantly reducing computational complexity; making it a promising framework to mitigate the new emerging network security threats in SDN.
引用
收藏
页数:6
相关论文
共 50 条
  • [21] Machine Learning-Based Detection of Ransomware Using SDN
    Cusack, Greg
    Michel, Oliver
    Keller, Eric
    PROCEEDINGS OF THE 2018 ACM INTERNATIONAL WORKSHOP ON SECURITY IN SOFTWARE DEFINED NETWORKS & NETWORK FUNCTION VIRTUALIZATION (SDN-NFVSEC'18), 2018, : 1 - 6
  • [22] DDoS Attacks Detection and Mitigation in SDN using Machine Learning
    Rahman, Obaid
    Quraishi, Mohammad Ali Gauhar
    Lung, Chung-Horng
    2019 IEEE WORLD CONGRESS ON SERVICES (IEEE SERVICES 2019), 2019, : 184 - 189
  • [23] Detection of DDoS Attack in IoT Using Machine Learning
    Kumar, Naveen
    Aleem, Abdul
    Kumar, Sachin
    ADVANCED NETWORK TECHNOLOGIES AND INTELLIGENT COMPUTING, ANTIC 2021, 2022, 1534 : 190 - 199
  • [24] Cloud Insider Attack Detection Using Machine Learning
    Nathezhtha, T.
    Vaidehi, V.
    PROCEEDINGS OF THE 2018 INTERNATIONAL CONFERENCE ON RECENT TRENDS IN ADVANCED COMPUTING (ICRTAC-CPS 2018), 2018, : 60 - 65
  • [25] Botnet Attack Detection in IoT Using Machine Learning
    Alissa, Khalid
    Alyas, Tahir
    Zafar, Kashif
    Abbas, Qaiser
    Tabassum, Nadia
    Sakib, Shadman
    COMPUTATIONAL INTELLIGENCE AND NEUROSCIENCE, 2022, 2022
  • [26] A DDoS Attack Detection on Cloud Framework Using Improved Features Based Machine Learning Approach
    Bhargav, Ravi
    Jain, Vishal
    Verma, Manish
    2022 SECOND INTERNATIONAL CONFERENCE ON ADVANCES IN ELECTRICAL, COMPUTING, COMMUNICATION AND SUSTAINABLE TECHNOLOGIES (ICAECT), 2022,
  • [27] Low Rate DoS Attack Detection in IoT - SDN using Deep Learning
    Ilango, Harun Surej
    Ma, Maode
    Su, Rong
    IEEE CONGRESS ON CYBERMATICS / 2021 IEEE INTERNATIONAL CONFERENCES ON INTERNET OF THINGS (ITHINGS) / IEEE GREEN COMPUTING AND COMMUNICATIONS (GREENCOM) / IEEE CYBER, PHYSICAL AND SOCIAL COMPUTING (CPSCOM) / IEEE SMART DATA (SMARTDATA), 2021, : 115 - 120
  • [28] A DDoS Attack Mitigation Scheme in ISP Networks Using Machine Learning Based on SDN
    Nguyen Ngoc Tuan
    Pham Huy Hung
    Nguyen Danh Nghia
    Nguyen Van Tho
    Trung Van Phan
    Nguyen Huu Thanh
    ELECTRONICS, 2020, 9 (03)
  • [29] Cooperative defense of DDoS attack based on machine learning in SDN
    Shang L.
    Chen M.
    Zhang L.
    Liu X.
    Shi T.
    Li B.
    Dianli Xitong Baohu yu Kongzhi/Power System Protection and Control, 2021, 49 (16): : 170 - 176
  • [30] Predicting Network Attack Patterns in SDN Machine Learning Approach
    Nanda, Saurav
    Zafari, Faheem
    DeCusatis, Casimer
    Wedaa, Eric
    Yang, Baijian
    2016 IEEE CONFERENCE ON NETWORK FUNCTION VIRTUALIZATION AND SOFTWARE DEFINED NETWORKS (NFV-SDN), 2016, : 167 - 172