Challenge-based collaborative intrusion detection in software-defined networking: an evaluation

被引:19
|
作者
Li, Wenjuan [1 ,2 ]
Wang, Yu [1 ]
Jin, Zhiping [3 ]
Yu, Keping [4 ]
Li, Jin [1 ]
Xiang, Yang [1 ]
机构
[1] Guangzhou Univ, Inst Artificial Intelligence & Blockchain, Guangzhou 510006, Peoples R China
[2] Tech Univ Denmark, Dept Appl Math & Comp Sci, DK-2800 Lyngby, Denmark
[3] Zhongshan Polytech, Sch Informat Engn, Zhongshan 528400, Guangdong, Peoples R China
[4] Waseda Univ, Global Informat & Telecommun Inst, Shinju Ku, Tokyo 1698050, Japan
基金
中国国家自然科学基金; 日本学术振兴会;
关键词
Software-defined networking; Trust management; Collaborative intrusion detection; Insider attack; Challenge mechanism; ALERT CORRELATION; TRUST; ATTACKS;
D O I
10.1016/j.dcan.2020.09.003
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
Software-Defined Networking (SDN) is an emerging architecture that enables a computer network to be intelligently and centrally controlled via software applications. It can help manage the whole network environment in a consistent and holistic way, without the need of understanding the underlying network structure. At present, SDN may face many challenges like insider attacks, i.e., the centralized control plane would be attacked by malicious underlying devices and switches. To protect the security of SDN, effective detection approaches are indispensable. In the literature, challenge-based Collaborative Intrusion Detection Networks (CIDNs) are an effective detection framework in identifying malicious nodes. It calculates the nodes' reputation and detects a malicious node by sending out a special message called a challenge. In this work, we devise a challenge-based CIDN in SDN and measure its performance against malicious internal nodes. Our results demonstrate that such a mechanism can be effective in SDN environments.
引用
收藏
页码:257 / 263
页数:7
相关论文
共 50 条
  • [1] Towards Blockchained Challenge-Based Collaborative Intrusion Detection
    Li, Wenjuan
    Wang, Yu
    Li, Jin
    Au, Man Ho
    [J]. APPLIED CRYPTOGRAPHY AND NETWORK SECURITY WORKSHOPS, 2019, 11605 : 122 - 139
  • [2] A Framework of Blockchain-Based Collaborative Intrusion Detection in Software Defined Networking
    Li, Wenjuan
    Tan, Jiao
    Wang, Yu
    [J]. NETWORK AND SYSTEM SECURITY, NSS 2020, 2020, 12570 : 261 - 276
  • [3] An Efficient Intrusion Detection Framework in Software-Defined Networking for Cybersecurity Applications
    Alshammri, Ghalib H.
    Samha, Amani K.
    Hemdan, Ezz El-Din
    Amoon, Mohammed
    El-Shafai, Walid
    [J]. CMC-COMPUTERS MATERIALS & CONTINUA, 2022, 72 (02): : 3529 - 3548
  • [4] Applying Transfer Learning Approaches for Intrusion Detection in Software-Defined Networking
    Chuang, Hsiu-Min
    Ye, Li-Jyun
    [J]. SUSTAINABILITY, 2023, 15 (12)
  • [5] BlockCSDN: Towards Blockchain-Based Collaborative Intrusion Detection in Software Defined Networking
    Li, Wenjuan
    Wang, Yu
    Meng, Weizhi
    Li, Jin
    Su, Chunhua
    [J]. IEICE TRANSACTIONS ON INFORMATION AND SYSTEMS, 2022, E105D (02) : 272 - 279
  • [6] Applying modified golden jackal optimization to intrusion detection for Software-Defined Networking
    Qiu, Feng
    Xu, Hui
    Li, Fukui
    [J]. ELECTRONIC RESEARCH ARCHIVE, 2024, 32 (01): : 418 - 444
  • [7] Toward a blockchain-based framework for challenge-based collaborative intrusion detection
    Wenjuan Li
    Yu Wang
    Jin Li
    Man Ho Au
    [J]. International Journal of Information Security, 2021, 20 : 127 - 139
  • [8] Toward a blockchain-based framework for challenge-based collaborative intrusion detection
    Li, Wenjuan
    Wang, Yu
    Li, Jin
    Au, Man Ho
    [J]. INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2021, 20 (02) : 127 - 139
  • [9] SDNIPS: Enabling Software-Defined Networking Based Intrusion Prevention System in Clouds
    Xing, Tianyi
    Xiong, Zhengyang
    Huang, Dijiang
    Medhi, Deep
    [J]. 2014 10TH INTERNATIONAL CONFERENCE ON NETWORK AND SERVICE MANAGEMENT (CNSM), 2014, : 308 - 311
  • [10] Risk based intrusion detection system in software defined networking
    Chetouane, Ameni
    Karoui, Kamel
    [J]. CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2024, 36 (09):