A Novel Machine Learning Framework for Advanced Attack Detection using SDN

被引:20
|
作者
Abou El Houda, Zakaria [1 ,3 ]
Hafid, Abdelhakim Senhaji [1 ]
Khoukhi, Lyes [2 ]
机构
[1] Univ Montreal, Dept Comp Sci & Operat Res, NRL, Montreal, PQ, Canada
[2] Normandie Univ, ENSICAEN, GREYC CNRS, Paris, France
[3] Univ Technol Troyes, Troyes, France
关键词
Machine Learning; Intrusion Detection System; Isolation Forest; SDN;
D O I
10.1109/GLOBECOM46510.2021.9685643
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Recently, software defined networks (SDN) has emerged as novel technology that leverages network programmability to facilitate network management. SDN provides a global view of the network, through a logically centralized component, called SDN controller, to strengthen network security. SDN separates the control plane from the data plane, which allows for a more control over the network and brings new capabilities to cope with the new emerging security threats (i.e., zero-day attacks). Existing attack detection schemes are facing obstacles due to high false positive rates, low detection performances, and high computational costs. To address these issues, we propose a multi-module Machine Learning (ML) framework that combines unsupervised ML techniques with a scalable feature collection and selection scheme to effectively/timely detect network security threats in the context of SDN. In particular, our proposed framework consists of: (1) a data flow collection module (DFC) to gather the features of network data in a scalable and efficient way using sFlow protocol; (2) an Information gain Feature Selection (IGF) module to select the most informative/relevant features to reduce training and testing time complexity; and (3) a novel unsupervised ML module that uses a novel outlier detection scheme, called Isolation Forest (ML-IF), to effectively/timely detect network security threats in SDN. The experimental results using the well-known public network security dataset UNSW-NB15, show that our proposed framework outperforms state-of-the-art contributions in terms of accuracy and detection rate while significantly reducing computational complexity; making it a promising framework to mitigate the new emerging network security threats in SDN.
引用
收藏
页数:6
相关论文
共 50 条
  • [31] A Comprehensive Analysis of Machine Learning- and Deep Learning-Based Solutions for DDoS Attack Detection in SDN
    Naziya Aslam
    Shashank Srivastava
    M. M. Gore
    Arabian Journal for Science and Engineering, 2024, 49 : 3533 - 3573
  • [32] DoS Attack Detection Based on Deep Factorization Machine in SDN
    Wang J.
    Lei X.
    Jiang Q.
    Alfarraj O.
    Tolba A.
    Kim G.-J.
    Computer Systems Science and Engineering, 2023, 45 (02): : 1727 - 1742
  • [33] A framework for extrusion detection using machine learning
    Luo, Yan
    Tsai, Jeffrey J. P.
    ISORC 2008: 11TH IEEE SYMPOSIUM ON OBJECT/COMPONENT/SERVICE-ORIENTED REAL-TIME DISTRIBUTED COMPUTING - PROCEEDINGS, 2008, : 83 - 88
  • [34] A Comprehensive Analysis of Machine Learning- and Deep Learning-Based Solutions for DDoS Attack Detection in SDN
    Aslam, Naziya
    Srivastava, Shashank
    Gore, M. M.
    ARABIAN JOURNAL FOR SCIENCE AND ENGINEERING, 2023, 49 (03) : 3897 - 3914
  • [35] AID-SDN: Advanced Intelligent Defense for SDN using P4 and Machine Learning
    Nascimento, Adiel
    Abreu, Diego
    Riker, Andre
    Abelem, Antonio
    2023 IEEE LATIN-AMERICAN CONFERENCE ON COMMUNICATIONS, LATINCOM, 2023,
  • [36] A New Framework for DDoS Attack Detection and Defense in SDN Environment
    Tan, Liang
    Pan, Yue
    Wu, Jing
    Zhou, Jianguo
    Jiang, Hao
    Deng, Yuchuan
    IEEE ACCESS, 2020, 8 : 161908 - 161919
  • [37] A Hierarchical Fog Computing Framework for Network Attack Detection in SDN
    Houda, Zakaria Abou El
    Khoukhi, Lyes
    IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC 2022), 2022, : 4366 - 4371
  • [38] Detection and Classification of Conflict Flows in SDN Using Machine Learning Algorithms
    Khairi, Mutaz Hamed Hussien
    Ariffin, Sharifah Hafizah Syed
    Latiff, Nurul Mu'Azzah Abdul
    Yusof, Kamaludin Mohamad
    Hassan, Mohamed Khalafalla
    Al-Dhief, Fahad Taha
    Hamdan, Mosab
    Khan, Suleman
    Hamzah, Muzaffar
    IEEE ACCESS, 2021, 9 (09): : 76024 - 76037
  • [39] Enhanced Scanning in SDN Networks and its Detection using Machine Learning
    Alqahtani, Abdullah H.
    Clark, John A.
    2022 IEEE 4TH INTERNATIONAL CONFERENCE ON TRUST, PRIVACY AND SECURITY IN INTELLIGENT SYSTEMS, AND APPLICATIONS, TPS-ISA, 2022, : 188 - 197
  • [40] Cybersecurity Attack Detection Model, Using Machine Learning Techniques
    Avci, Isa
    Koca, Murat
    ACTA POLYTECHNICA HUNGARICA, 2023, 20 (07) : 29 - 44