Scalable Traffic Sampling Using Centrality Measure on Software-Defined Networks

被引:37
|
作者
Yoon, Seunghyun [1 ]
Ha, Taejin [1 ]
Kim, Sunghwan [1 ]
Lim, Hyuk [1 ]
机构
[1] Gwangju Inst Sci & Technol, Gwangju, South Korea
关键词
D O I
10.1109/MCOM.2017.1600990
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
With regard to cyber security, pervasive traffic visibility is one of the most essential functionalities for complex network systems. A traditional network system has limited access to core and edge switches on the network; on the other hand, SDN technology can provide flexible and programmable network management operations. In this article, we consider the practical problem concerning how to achieve scalable traffic measurement using SDN functionalities. Less intrusive traffic monitoring can be achieved by using a packet sampling technique that probabilistically captures data packets at switches, and the sampled traffic is steered toward a traffic analyzer such as an IDS on SDN. We propose the use of a centrality measure in graph theory for deciding the traffic sampling points among the switches. In addition, we discuss how to decide the traffic sampling rates at the selected switches. The results of the simulation and SDN testbed experiments indicate that the proposed sampling point and rate decision methods enhance the intrusion detection performance of an IDS in terms of malicious traffic flows in large-scale networks.
引用
收藏
页码:43 / 49
页数:7
相关论文
共 50 条
  • [1] Suspicious traffic sampling for intrusion detection in software-defined networks
    Ha, Taejin
    Kim, Sunghwan
    An, Namwon
    Narantuya, Jargalsaikhan
    Jeong, Chiwook
    Kim, JongWon
    Lim, Hyuk
    [J]. COMPUTER NETWORKS, 2016, 109 : 172 - 182
  • [2] Scalable Service Deployment on Software-Defined Networks
    Rubio-Loyola, Javier
    Galis, Alex
    Astorga, Antonio
    Serrat, Joan
    Lefevre, Laurent
    Fischer, Andreas
    Paler, Alexandru
    de Meer, Hermann
    [J]. IEEE COMMUNICATIONS MAGAZINE, 2011, 49 (12) : 84 - 93
  • [3] Scalable Network Virtualization in Software-Defined Networks
    Drutskoy, Dmitry
    Keller, Eric
    Rexford, Jennifer
    [J]. IEEE INTERNET COMPUTING, 2013, 17 (02) : 20 - 27
  • [4] Multicast Traffic Engineering for Software-Defined Networks
    Huang, Liang-Hao
    Hsu, Hsiang-Chun
    Shen, Shan-Hsiang
    Yang, De-Nian
    Chen, Wen-Tsuen
    [J]. IEEE INFOCOM 2016 - THE 35TH ANNUAL IEEE INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATIONS, 2016,
  • [5] Modeling Control Traffic in Software-Defined Networks
    Chen, Jesse
    Gopal, Ananya
    Dezfouli, Behnam
    [J]. PROCEEDINGS OF THE 2021 IEEE 7TH INTERNATIONAL CONFERENCE ON NETWORK SOFTWARIZATION (NETSOFT 2021): ACCELERATING NETWORK SOFTWARIZATION IN THE COGNITIVE AGE, 2021, : 258 - 262
  • [6] Control Traffic Protection in Software-Defined Networks
    Hu, Yannan
    Wang Wendong
    Gong Xiangyang
    Liu, Chi Harold
    Que, Xirong
    Cheng, Shiduan
    [J]. 2014 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM 2014), 2014, : 1878 - 1883
  • [7] SEMTE: scalable and extended modular traffic engineering in software-defined data center networks
    Majma, Mohammad Reza
    Nejad, Emad Soltani
    [J]. PHOTONIC NETWORK COMMUNICATIONS, 2021, 42 (03) : 143 - 166
  • [8] SEMTE: scalable and extended modular traffic engineering in software-defined data center networks
    Mohammad Reza Majma
    Emad Soltani Nejad
    [J]. Photonic Network Communications, 2021, 42 : 143 - 166
  • [9] Scalable explicit path control in software-defined networks
    Luo, Long
    Yu, Hongfang
    Luo, Shouxi
    Ye, Zilong
    Du, Xiaojiang
    Guizani, Mohsen
    [J]. JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2019, 141 : 86 - 103
  • [10] SSDWSN: A Scalable Software-Defined Wireless Sensor Networks
    Alsaeedi, Mohammed
    Mohamad, Mohd Murtadha
    Al-Roubaiey, Anas
    [J]. IEEE ACCESS, 2024, 12 : 21787 - 21806