ANOMALY DETECTION IN ATM-GRADE SOFTWARE DEFINED NETWORKS

被引:0
|
作者
Lellek, Philipp [1 ]
Leydold, Peter [1 ]
Vojnoski, Igor [1 ]
Eier, Dieter [2 ]
机构
[1] Frequentis AG, Vienna, Austria
[2] Frequentis USA, Columbia, MD USA
关键词
D O I
10.1109/ICNS52807.2021.9441630
中图分类号
V [航空、航天];
学科分类号
08 ; 0825 ;
摘要
The Federal Aviation Administration (FAA) and Air Navigation Service Providers (ANSPs) around the world are looking to share data and get interconnected with each other as well as data service consumers. This interconnectivity enables new functionality but also new attack vectors. Today, agencies mostly rely on commercial security solutions providing adequate protection for commercial data services but have deficiencies when it comes to the Air Traffic Management (ATM) environment with its requirement for highest resilience, multi-level redundancies, and dynamic environment. This paper introduces a novel approach to create an ATM-grade baseline integrating operational security events (OSE) and alerts (OSA) based on abnormal or malicious network traffic. An assured and trusted baseline is key to detecting atypical or malicious traffic. A testbed has been developed that models the regular ATM-grade IP-network behavior. The sample configuration uses open source stacks ElastiFlow, and SELKS to provide network flow data collection and visualization and demonstrate resilience against hacking attempts via unauthorized communication and protocols between nodes, unauthorized configuration changes via distribution of parameters to network nodes, as well as detection of malicious communication attempts from unauthorized devices on the network. A Software Defined Network (SDN) architecture is chosen as it features a programmable, efficient network configuration improving network performance and monitoring. The OpenFlow protocol is used to provide the control plane in the testbed. Data flows will be modeled as synchronous as well as asynchronous. Vulnerabilities are then identified, attack scenarios defined and applied to the testbed setup. The available SDN platform tools are then used to detect the anomalies. Sets of experiments are performed and the results compared and discussed.
引用
收藏
页数:8
相关论文
共 50 条
  • [31] Software-Defined-Networking-Enabled Traffic Anomaly Detection and Mitigation
    He, Daojing
    Chan, Sammy
    Ni, Xiejun
    Guizani, Mohsen
    [J]. IEEE INTERNET OF THINGS JOURNAL, 2017, 4 (06): : 1890 - 1898
  • [32] RADS: a real-time anomaly detection model for software-defined networks using machine learning
    Sneha, M.
    Kumar, A. Keerthan
    Hegde, Nikhil V.
    Anish, A. S.
    Shobha, G.
    [J]. INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2023, 22 (06) : 1881 - 1891
  • [33] RADS: a real-time anomaly detection model for software-defined networks using machine learning
    M. Sneha
    A. Keerthan Kumar
    Nikhil V. Hegde
    A. S. Anish
    G. Shobha
    [J]. International Journal of Information Security, 2023, 22 : 1881 - 1891
  • [34] Correction: Flow-based intrusion detection on software-defined networks: a multivariate time series anomaly detection approach
    Sultan Zavrak
    Murat Iskefiyeli
    [J]. Neural Computing and Applications, 2023, 35 : 18091 - 18091
  • [35] Detection and Mitigation of DoS Attacks in Software Defined Networks
    Gao, Shang
    Peng, Zhe
    Xiao, Bin
    Hu, Aiqun
    Song, Yubo
    Ren, Kui
    [J]. IEEE-ACM TRANSACTIONS ON NETWORKING, 2020, 28 (03) : 1419 - 1433
  • [36] Entropy based DDoS Detection in Software Defined Networks
    Fioravanti, Giovanni
    Spina, Mattia Giovanni
    De Rango, Floriano
    [J]. 2023 IEEE 20TH CONSUMER COMMUNICATIONS & NETWORKING CONFERENCE, CCNC, 2023,
  • [37] A Heavy Hitter Detection Mechanism in Software Defined Networks
    Xing C.-Y.
    Li D.-Y.
    Xie S.-X.
    Zhang G.-M.
    Wei W.
    [J]. Beijing Youdian Daxue Xuebao/Journal of Beijing University of Posts and Telecommunications, 2020, 43 (01): : 97 - 103
  • [38] Mitigation and Detection of DDoS Attacks in Software Defined Networks
    Murtuza, Shariq
    Asawa, Krishna
    [J]. 2018 ELEVENTH INTERNATIONAL CONFERENCE ON CONTEMPORARY COMPUTING (IC3), 2018, : 389 - 391
  • [39] Robust and Agile System against Fault and Anomaly Traffic in Software Defined Networks
    Kim, Mihui
    Park, Younghee
    Kotalwar, Rohit
    [J]. APPLIED SCIENCES-BASEL, 2017, 7 (03):
  • [40] The Devil is in the Details: Confident & Explainable Anomaly Detector for Software-Defined Networks
    Das, Tapadhir
    Shukla, Raj Mani
    Sengupta, Shamik
    [J]. 2021 IEEE 20TH INTERNATIONAL SYMPOSIUM ON NETWORK COMPUTING AND APPLICATIONS (NCA), 2021,