ANOMALY DETECTION IN ATM-GRADE SOFTWARE DEFINED NETWORKS

被引:0
|
作者
Lellek, Philipp [1 ]
Leydold, Peter [1 ]
Vojnoski, Igor [1 ]
Eier, Dieter [2 ]
机构
[1] Frequentis AG, Vienna, Austria
[2] Frequentis USA, Columbia, MD USA
关键词
D O I
10.1109/ICNS52807.2021.9441630
中图分类号
V [航空、航天];
学科分类号
08 ; 0825 ;
摘要
The Federal Aviation Administration (FAA) and Air Navigation Service Providers (ANSPs) around the world are looking to share data and get interconnected with each other as well as data service consumers. This interconnectivity enables new functionality but also new attack vectors. Today, agencies mostly rely on commercial security solutions providing adequate protection for commercial data services but have deficiencies when it comes to the Air Traffic Management (ATM) environment with its requirement for highest resilience, multi-level redundancies, and dynamic environment. This paper introduces a novel approach to create an ATM-grade baseline integrating operational security events (OSE) and alerts (OSA) based on abnormal or malicious network traffic. An assured and trusted baseline is key to detecting atypical or malicious traffic. A testbed has been developed that models the regular ATM-grade IP-network behavior. The sample configuration uses open source stacks ElastiFlow, and SELKS to provide network flow data collection and visualization and demonstrate resilience against hacking attempts via unauthorized communication and protocols between nodes, unauthorized configuration changes via distribution of parameters to network nodes, as well as detection of malicious communication attempts from unauthorized devices on the network. A Software Defined Network (SDN) architecture is chosen as it features a programmable, efficient network configuration improving network performance and monitoring. The OpenFlow protocol is used to provide the control plane in the testbed. Data flows will be modeled as synchronous as well as asynchronous. Vulnerabilities are then identified, attack scenarios defined and applied to the testbed setup. The available SDN platform tools are then used to detect the anomalies. Sets of experiments are performed and the results compared and discussed.
引用
收藏
页数:8
相关论文
共 50 条
  • [41] Entropy-KL-ML:Enhancing the Entropy-KL-Based Anomaly Detection on Software-Defined Networks
    Niknami, Nadia
    Wu, Jie
    [J]. IEEE TRANSACTIONS ON NETWORK SCIENCE AND ENGINEERING, 2022, 9 (06): : 4458 - 4467
  • [42] Security anomaly detection in software-defined networking based on a prediction technique
    Jafarian, Tohid
    Masdari, Mohammad
    Ghaffari, Ali
    Majidzadeh, Kambiz
    [J]. INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2020, 33 (14)
  • [43] Deep Learning Based Anomaly Detection Scheme in Software-Defined Networking
    Qin, Yang
    Wei, Junjie
    Yang, Weihong
    [J]. 2019 20TH ASIA-PACIFIC NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM (APNOMS), 2019,
  • [44] Software Defined Networks
    Leon-Garcia, Alberto
    Ashwood-Smith, Peter
    Ganjali, Yashar
    [J]. COMPUTER NETWORKS, 2015, 92 : 209 - 210
  • [45] SOFTWARE DEFINED NETWORKS
    Li, Chung-Sheng
    Liao, Wanjiun
    [J]. IEEE COMMUNICATIONS MAGAZINE, 2013, 51 (02) : 113 - 113
  • [46] SOFTWARE DEFINED NETWORKS
    Doughty, Mark
    [J]. JOURNAL OF THE INSTITUTE OF TELECOMMUNICATIONS PROFESSIONALS, 2015, 9 : 40 - 44
  • [47] Predictive analysis for race detection in software-defined networks
    Lu, Gongzheng
    Xu, Lei
    Yang, Yibiao
    Xu, Baowen
    [J]. SCIENCE CHINA-INFORMATION SCIENCES, 2019, 62 (06)
  • [48] Detection of Distributed Denial of Service Attacks in Software Defined Networks
    Barki, Lohit
    Shidling, Amrit
    Meti, Nisharani
    Narayan, D. G.
    Mulla, Mohammed Moin
    [J]. 2016 INTERNATIONAL CONFERENCE ON ADVANCES IN COMPUTING, COMMUNICATIONS AND INFORMATICS (ICACCI), 2016, : 2576 - 2581
  • [49] Collaborative detection and mitigation of DDoS in software-defined networks
    Omer Elsier Tayfour
    Muhammad Nadzir Marsono
    [J]. The Journal of Supercomputing, 2021, 77 : 13166 - 13190
  • [50] Examining the Security of DDoS Detection Systems in Software Defined Networks
    Abusnaina, Ahmed
    Nyang, DaeHun
    Yuksel, Murat
    Mohaisen, Aziz
    [J]. CONEXT'19 COMPANION: PROCEEDINGS OF THE 15TH INTERNATIONAL CONFERENCE ON EMERGING NETWORKING EXPERIMENTS AND TECHNOLOGIES, 2019, : 49 - 50