Detecting malicious packet drops and misroutings using Header Space Analysis

被引:0
|
作者
Mohammadi, Amir Ahmad [1 ]
Kazemian, Peyman [2 ,3 ]
Pakravan, Mohammad Reza [1 ]
机构
[1] Sharif Univ Technol, Dept Elect Engn, Data Networks Res Lab, Tehran, Iran
[2] Stanford Univ, Stanford, CA 94305 USA
[3] Forward Networks, Palo Alto, CA USA
关键词
D O I
暂无
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
Software Defined Networking (SDN) provides a logically centralized view of the state of the network, and as a result opens up new ways to manage and monitor networks. In this paper we introduce a novel approach to network intrusion detection in SDNs that takes advantage of these attributes. Our approach can detect compromised routers that produce faulty messages, copy or steal traffic or maliciously drop certain types of packets. To identify these attacks and the affected switches, we correlate the forwarding state of network-i.e. installed forwarding rules-with the forwarding status of packets-i.e. the actual route packets take in the network and detect anomaly in routes. Thus, our approach turns the network itself into a big intrusion detection system. We have evaluated our approach on topologies from real networks by developing an application over OpenDaylight SDN controller and detected simulated dropping and duplicating attacks in these networks.
引用
收藏
页码:521 / 526
页数:6
相关论文
共 50 条
  • [1] Network Packet Analysis For Detecting Malicious Insider
    Patil, Dinesh
    Meshram, Bandu
    [J]. 2018 3RD INTERNATIONAL CONFERENCE FOR CONVERGENCE IN TECHNOLOGY (I2CT), 2018,
  • [2] Detecting Malicious Packet Losses
    Mizrak, Alper T.
    Savage, Stefan
    Marzullo, Keith
    [J]. IEEE TRANSACTIONS ON PARALLEL AND DISTRIBUTED SYSTEMS, 2009, 20 (02) : 191 - 206
  • [3] Detecting malicious packet dropping using statistical traffic patterns
    Julian, Benadit P.
    Sharmila, Baskaran
    Ramya, Taimanessamy
    [J]. International Journal of Computer Science Issues, 2011, 8 (3 3-2): : 121 - 126
  • [4] Detecting Malicious Node in Network Using Packet Delivery Ratio
    Tyagi, Sanjay
    Gopal, Girdliar
    Garg, Vikas
    [J]. PROCEEDINGS OF THE 10TH INDIACOM - 2016 3RD INTERNATIONAL CONFERENCE ON COMPUTING FOR SUSTAINABLE GLOBAL DEVELOPMENT, 2016, : 3313 - 3318
  • [5] Detecting traffic anomalies through aggregate analysis of packet header data
    Kim, SS
    Reddy, ALN
    Vannucci, M
    [J]. NETWORKING 2004: NETWORKING TECHNOLOGIES, SERVICES, AND PROTOCOLS; PERFORMANCE OF COMPUTER AND COMMUNICATION NETWORKS; MOBILE AND WIRELESS COMMUNICATIONS, 2004, 3042 : 1047 - 1059
  • [6] A Comprehensive Evaluation of HTTP Header Features for Detecting Malicious Websites
    McGahagan, John
    Bhansali, Darshan
    Gratian, Margaret
    Cukier, Michel
    [J]. 2019 15TH EUROPEAN DEPENDABLE COMPUTING CONFERENCE (EDCC 2019), 2019, : 75 - 82
  • [7] Packet Header Anomaly Detection Using Statistical Analysis
    Yassin, Warusia
    Udzir, Nur Izura
    Abdullah, Azizol
    Abdullah, Mohd Taufik
    Muda, Zaiton
    Zulzalil, Hazura
    [J]. INTERNATIONAL JOINT CONFERENCE SOCO'14-CISIS'14-ICEUTE'14, 2014, 299 : 473 - 482
  • [8] Monitoring Agent for Detecting Malicious Packet Drops for Wireless Sensor Networks in the Microgrid and Grid-enabled Vehicles
    Ko, Jongbin
    Seo, Jungtaek
    Kim, Eui-Jik
    Shon, Taeshik
    [J]. INTERNATIONAL JOURNAL OF ADVANCED ROBOTIC SYSTEMS, 2012, 9
  • [9] HyPaFilter plus : Enhanced Hybrid Packet Filtering Using Hardware Assisted Classification and Header Space Analysis
    Fiessler, Andreas
    Lorenz, Claas
    Hager, Sven
    Scheuermann, Bjoern
    Moore, Andrew W.
    [J]. IEEE-ACM TRANSACTIONS ON NETWORKING, 2017, 25 (06) : 3655 - 3669
  • [10] Detecting Malicious URLs Using Lexical Analysis
    Mamun, Mohammad Saiful Islam
    Rathore, Mohammad Ahmad
    Lashkari, Arash Habibi
    Stakhanova, Natalia
    Ghorbani, Ali A.
    [J]. NETWORK AND SYSTEM SECURITY, (NSS 2016), 2016, 9955 : 467 - 482