Network Intrusion Detection And Prevention Middlebox Management In SDN

被引:0
|
作者
Wang, Wen [1 ]
He, Wenbo [1 ]
Su, Jinshu [2 ]
机构
[1] McGill Univ, Sch Comp Sci, Montreal, PQ, Canada
[2] Natl Univ Def Technol, Sch Comp, Changsha, Hunan, Peoples R China
关键词
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
In traditional networks, it is difficult to manage the distributed detection and prevention nodes of IDS and IPS due to the laborious manual deployment and independent configuration. Software defined networking (SDN) provides a flexible approach to control the underlying network infrastructures efficiently. However, the OpenFlow flow table is too simple to provide complex functions with the match-action style processing. To support more functionalities, in this paper, we propose a middlebox management architecture with SDN OpenMiddlebox, by extending OpenFlow to support middleboxes with ClickOS virtual machines (VM), so that programmable middleboxes could be deployed and managed in switches with fast booted ClickOS VMs flexibly. We then design automatic deployment and update schemes of network intrusion detection and prevention middleboxes with the centralized controller. The evaluation results show that OpenMiddlebox could manage the distributed middleboxes efficiently and is scalable to large networks, and the centralized control also improves the network intrusion detection and prevention accuracy.
引用
收藏
页数:8
相关论文
共 50 条
  • [1] Implementation of SDN Based Network Intrusion Detection and Prevention System
    Chen, Pin-Jui
    Chen, Yen-Wen
    49TH ANNUAL IEEE INTERNATIONAL CARNAHAN CONFERENCE ON SECURITY TECHNOLOGY (ICCST), 2015, : 141 - 146
  • [2] Design of network intrusion prevention system based on SDN
    Gong J.
    Jin L.
    2016, Huazhong University of Science and Technology (44): : 1 - 6
  • [3] Policy management for network-based intrusion detection and prevention
    Chen, YM
    Yang, YY
    NOMS 2004: IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM, APPLICATION SESSIONS: MANAGING NEXT GENERATION CONVERGENCE NETWORKS AND SERVICES, 2004, : 219 - 232
  • [4] CIPA: A collaborative intrusion prevention architecture for programmable network and SDN
    Chen, Xiao-Fan
    Yu, Shun-Zheng
    COMPUTERS & SECURITY, 2016, 58 : 1 - 19
  • [5] Scalable Network Intrusion Detection on Virtual SDN Environment
    Jeong, Chiwook
    Ha, Taejin
    Narantuya, Jargalsaikhan
    Lim, Hyuk
    kim, Jongwon
    2014 IEEE 3RD INTERNATIONAL CONFERENCE ON CLOUD NETWORKING (CLOUDNET), 2014, : 264 - 265
  • [6] Network management system with intrusion prevention
    Chen, YC
    Wang, TC
    2005 Beijing International Conference on Imaging: Technology and Applications for the 21st Century, 2005, : 180 - 181
  • [7] An Intrusion Detection Model for Drone Communication Network in SDN Environment
    Kou, Liang
    Ding, Shanshuo
    Wu, Ting
    Dong, Wei
    Yin, Yuyu
    DRONES, 2022, 6 (11)
  • [8] Intrusion Detection and Mitigation Framework for SDN Controlled IoTs Network
    Zaheer, Amer
    Asghar, Muhammad Zeeshan
    Qayyum, Amir
    2021 IEEE 18TH INTERNATIONAL CONFERENCE ON SMART COMMUNITIES: IMPROVING QUALITY OF LIFE USING ICT, IOT AND AI (IEEE HONET 2021), 2021, : 147 - 151
  • [9] A Centralized Management Framework of Network-based Intrusion Detection and Prevention System
    Wonghirunsombat, Ekgapark
    Asawaniwed, Teewalee
    Hanchana, Vassapon
    Wattanapongsakorn, Naruemon
    Srakaew, Sanan
    Charnsripinyo, Chalermpol
    2013 10TH INTERNATIONAL JOINT CONFERENCE ON COMPUTER SCIENCE AND SOFTWARE ENGINEERING (JCSSE), 2013, : 183 - 188
  • [10] A New Architecture for Network Intrusion Detection and Prevention
    Bul'Ajoul, Waleed
    James, Anne
    Shaikh, Siraj
    IEEE ACCESS, 2019, 7 : 18558 - 18573