首页> 外文期刊>Journal of network and computer applications >Implementing an intrusion detection and prevention system using software-defined networking: Defending against port-scanning and denial-of-service attacks
【24h】

Implementing an intrusion detection and prevention system using software-defined networking: Defending against port-scanning and denial-of-service attacks

机译:使用软件定义网络实现入侵检测和预防系统:防御端口扫描和拒绝服务攻击

获取原文
获取原文并翻译 | 示例
           

摘要

Over recent years, we have observed a significant increase in the number and the sophistication of cyber attacks targeting home users, businesses, government organizations and even critical infrastructure. In many cases, it is important to detect attacks at the very early stages, before significant damage can be caused to networks and protected systems, including accessing sensitive data. To this end, cybersecurity researchers and professionals are exploring the use of Software-Defined Networking (SDN) technology for efficient and real-time defense against cyberattacks. SDN enables network control to be logically centralised by decoupling the control plane from the data plane. This feature enables network programmability and has the potential to almost instantly block network traffic when some malicious activity is detected.In this work, we design and implement an Intrusion Detection and Prevention System (IDPS) using SDN. Our IDPS is a software-application that monitors networks and systems for malicious activities or security policy violations and takes steps to mitigate such activity. We specifically focus on defending against port-scanning and Denial of Service (DoS) attacks. However, the proposed design and detection methodology has the potential to be expanded to a wide range of other malicious activities. We have implemented and tested two connection-based techniques as part of the IDPS, namely the Credit-Based Threshold Random Walk (CB-TRW) and Rate Limiting (RL). As a mechanism to defend against port-scanning, we outline and test our Port Bingo (PB) algorithm. Furthermore, we include QoS as a DoS attack mitigation, which relies on flow-statistics from a network switch. We conducted extensive experiments in a purpose-built testbed environment. The experimental results show that the launched port-scanning and DoS attacks can be detected and stopped in real-time. Finally, the rate of false positives can be kept sufficiently low by tuning the threshold parameters of the detection algorithms.
机译:近年来,我们已经观察到了对目标用户,企业,政府组织甚至关键基础设施的网络攻击的数量和复杂性的重大增加。在许多情况下,重要的是在对网络和保护系统中可能导致大量损坏之前检测到非常早期阶段的攻击,包括访问敏感数据。为此,网络安全研究人员和专业人员正在探索使用软件定义的网络(SDN)技术,以实现对抗网络攻击的高效和实时防御。 SDN使网络控制能够通过从数据平面解耦控制平面来逻辑集中。此功能使网络可编程性能够在检测到某些恶意活动时几乎立即瞬间阻止网络流量。在此工作中,我们使用SDN设计和实现入侵检测和预防系统(IDP)。我们的IDPS是一个软件应用程序,用于监控用于恶意活动或安全策略违规的网络和系统,并采取措施减轻此类活动。我们专注于防御抵御端口扫描和拒绝服务(DOS)攻击。然而,所提出的设计和检测方法具有扩展到各种其他恶意活动的可能性。我们已经实现并测试了基于两个连接的技术作为IDP的一部分,即基于信用的阈值随机步行(CB-TRW)和速率限制(RL)。作为防御端口扫描的机制,我们大纲和测试我们的端口宾果(PB)算法。此外,我们将QoS作为DOS攻击缓解,这依赖于网络交换机的流统计数据。我们在目的建立的测试平面环境中进行了广泛的实验。实验结果表明,可以在实时检测和停止发射的端口扫描和DOS攻击。最后,通过调整检测算法的阈值参数,可以保持误报的速率。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号