首页> 外文会议>Integrated Communications Navigation and Surveillance Conference >Anomaly Detection in Atm-Grade Software Defined Networks
【24h】

Anomaly Detection in Atm-Grade Software Defined Networks

机译:ATM级软件定义网络中的异常检测

获取原文

摘要

The Federal Aviation Administration (FAA) and Air Navigation Service Providers (ANSPs) around the world are looking to share data and get interconnected with each other as well as data service consumers. This interconnectivity enables new functionality but also new attack vectors.Today, agencies mostly rely on commercial security solutions providing adequate protection for commercial data services but have deficiencies when it comes to the Air Traffic Management (ATM) environment with its requirement for highest resilience, multi-level redundancies, and dynamic environment.This paper introduces a novel approach to create an ATM-grade baseline integrating operational security events (OSE) and alerts (OSA) based on abnormal or malicious network traffic. An assured and trusted baseline is key to detecting atypical or malicious traffic. A testbed has been developed that models the regular ATM-grade IP-network behavior. The sample configuration uses open source stacks ElastiFlow, and SELKS to provide network flow data collection and visualization and demonstrate resilience against hacking attempts via unauthorized communication and protocols between nodes, unauthorized configuration changes via distribution of parameters to network nodes, as well as detection of malicious communication attempts from unauthorized devices on the network. A Software Defined Network (SDN) architecture is chosen as it features a programmable, efficient network configuration improving network performance and monitoring. The OpenFlow protocol is used to provide the control plane in the testbed. Data flows will be modeled as synchronous as well as asynchronous. Vulnerabilities are then identified, attack scenarios defined and applied to the testbed setup. The available SDN platform tools are then used to detect the anomalies. Sets of experiments are performed and the results compared and discussed.
机译:世界各地的联邦航空管理局(FAA)和空中航行服务提供商(ANSPS)正在寻求共享数据并相互互连以及数据服务消费者。这种互连性能够实现新功能,也是新的攻击向量.Today,代理商大多依赖于商业安全解决方案,为商业数据服务提供充足的保护,但在空中交通管理(ATM)环境中具有最高弹性的要求,多 - redundancies和动态环境。本文介绍了一种新颖的方法,可以根据异常或恶意网络流量创建ATM级基准整合运行安全事件(OSA)和警报(OSA)。保证和可信赖的基线是检测到非典型或恶意交通的关键。已经开发了一个测试床,模拟了常规的ATM级IP网络行为。示例配置使用开源堆栈Elastiflow,并且Selks提供网络流数据收集和可视化,并通过未经授权的通信和节点之间的协议来证明恢复功能,通过对节点之间的未授权配置更改为网络节点,以及检测恶意的检测来自网络上未经授权设备的通信尝试。选择一个软件定义的网络(SDN)架构,因为它具有可编程,高效的网络配置,提高了网络性能和监控。 OpenFlow协议用于在测试器中提供控制平面。数据流将被建模为同步和异步。然后识别出漏洞,定义并应用于测试用平面的攻击场景。然后使用可用的SDN平台工具来检测异常。进行一组实验,并进行比较和讨论的结果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号