ANOMALY DETECTION IN ATM-GRADE SOFTWARE DEFINED NETWORKS

被引:0
|
作者
Lellek, Philipp [1 ]
Leydold, Peter [1 ]
Vojnoski, Igor [1 ]
Eier, Dieter [2 ]
机构
[1] Frequentis AG, Vienna, Austria
[2] Frequentis USA, Columbia, MD USA
关键词
D O I
10.1109/ICNS52807.2021.9441630
中图分类号
V [航空、航天];
学科分类号
08 ; 0825 ;
摘要
The Federal Aviation Administration (FAA) and Air Navigation Service Providers (ANSPs) around the world are looking to share data and get interconnected with each other as well as data service consumers. This interconnectivity enables new functionality but also new attack vectors. Today, agencies mostly rely on commercial security solutions providing adequate protection for commercial data services but have deficiencies when it comes to the Air Traffic Management (ATM) environment with its requirement for highest resilience, multi-level redundancies, and dynamic environment. This paper introduces a novel approach to create an ATM-grade baseline integrating operational security events (OSE) and alerts (OSA) based on abnormal or malicious network traffic. An assured and trusted baseline is key to detecting atypical or malicious traffic. A testbed has been developed that models the regular ATM-grade IP-network behavior. The sample configuration uses open source stacks ElastiFlow, and SELKS to provide network flow data collection and visualization and demonstrate resilience against hacking attempts via unauthorized communication and protocols between nodes, unauthorized configuration changes via distribution of parameters to network nodes, as well as detection of malicious communication attempts from unauthorized devices on the network. A Software Defined Network (SDN) architecture is chosen as it features a programmable, efficient network configuration improving network performance and monitoring. The OpenFlow protocol is used to provide the control plane in the testbed. Data flows will be modeled as synchronous as well as asynchronous. Vulnerabilities are then identified, attack scenarios defined and applied to the testbed setup. The available SDN platform tools are then used to detect the anomalies. Sets of experiments are performed and the results compared and discussed.
引用
收藏
页数:8
相关论文
共 50 条
  • [21] EFFICIENT ANOMALY DETECTION AND MITIGATION IN SOFTWARE DEFINED NETWORKING ENVIRONMENT
    Sathya, R.
    Thangarajan, R.
    [J]. 2015 2ND INTERNATIONAL CONFERENCE ON ELECTRONICS AND COMMUNICATION SYSTEMS (ICECS), 2015, : 479 - 484
  • [22] Unsupervised online anomaly detection in Software Defined Network environments
    Scaranti, Gustavo Frigo
    Carvalho, Luiz Fernando
    Barbon, Sylvio
    Lloret, Jaime
    Proenca, Mario Lemes
    [J]. EXPERT SYSTEMS WITH APPLICATIONS, 2022, 191
  • [23] An ecosystem for anomaly detection and mitigation in software-defined networking
    Carvalho, Luiz Fernando
    Abrao, Taufik
    Mendes, Leonardo de Souza
    Proenca, Mario Lemes, Jr.
    [J]. EXPERT SYSTEMS WITH APPLICATIONS, 2018, 104 : 121 - 133
  • [24] Revisiting Traffic Anomaly Detection Using Software Defined Networking
    Mehdi, Syed Akbar
    Khalid, Junaid
    Khayam, Syed Ali
    [J]. RECENT ADVANCES IN INTRUSION DETECTION, 2011, 6961 : 161 - 180
  • [25] An Approach for Detection of Attacks in Software Defined Networks
    Chippalkatti, Omkar
    Nimbhorkar, S. U.
    [J]. 2017 INTERNATIONAL CONFERENCE ON INNOVATIONS IN INFORMATION, EMBEDDED AND COMMUNICATION SYSTEMS (ICIIECS), 2017,
  • [26] Dynamic behavioral profiling for anomaly detection in software-defined IoT networks: A machine learning approach
    Senthilraja, P.
    Palaniappan, Kanmani
    Duraipandi, Brindha
    Balasubramanian, Uma Maheswari
    [J]. PEER-TO-PEER NETWORKING AND APPLICATIONS, 2024, 17 (04) : 2450 - 2469
  • [27] Flow-based intrusion detection on software-defined networks: a multivariate time series anomaly detection approach
    Sultan Zavrak
    Murat Iskefiyeli
    [J]. Neural Computing and Applications, 2023, 35 : 12175 - 12193
  • [28] Flow-based intrusion detection on software-defined networks: a multivariate time series anomaly detection approach
    Zavrak, Sultan
    Iskefiyeli, Murat
    [J]. NEURAL COMPUTING & APPLICATIONS, 2023, 35 (16): : 12175 - 12193
  • [29] Anomaly-Free Policy Composition in Software-Defined Networks
    Rezvani, Mohsen
    Ignjatovic, Aleksandar
    Pagnucco, Maurice
    Jha, Sanjay
    [J]. 2016 IFIP NETWORKING CONFERENCE (IFIP NETWORKING) AND WORKSHOPS, 2016, : 28 - 36
  • [30] Practical Performance Degradation Mitigation Solution using Anomaly Detection for Carrier-Grade Software Networks
    Corici, Marius
    Buda, Teodora Sandra
    Shrestha, Ranjan
    Cau, Eleonora
    Metin, Taner
    Assem, Haytham
    [J]. 2018 IEEE CONFERENCE ON STANDARDS FOR COMMUNICATIONS AND NETWORKING (IEEE CSCN), 2018,