Entropy-KL-ML:Enhancing the Entropy-KL-Based Anomaly Detection on Software-Defined Networks

被引:16
作者
Niknami, Nadia [1 ]
Wu, Jie [1 ]
机构
[1] Temple Univ, Dept Comp & Informat Sci, Philadelphia, PA 19122 USA
来源
IEEE TRANSACTIONS ON NETWORK SCIENCE AND ENGINEERING | 2022年 / 9卷 / 06期
基金
美国国家科学基金会;
关键词
Entropy; Control systems; Denial-of-service attack; IP networks; Feature extraction; Anomaly detection; Bandwidth; Software defined networking; classification; controller; denial of service (DoS) attacks; entropy; feature selection; SDN;
D O I
10.1109/TNSE.2022.3202147
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
The Software-Defined Networking (SDN) concept allows network innovations by leveraging a centralized controller that commands the whole network. The controller manages the functionality of the entire network. In the event that the controller fails, the switches will attempt to continue to forward traffic based on the last set of entries in the forwarding table. Therefore, assuming an unstable network, no interruption can be expected. Consequently, when a controller fails due to an expiration time or capacity limitation for a forwarding table, the controller will not be able to handle newly arriving packets. This will result in the entire network going down. Because of vulnerabilities between the control plane and the data plane, Denial of Service (DoS) attacks often pose the greatest risk to SDN. The paper discusses a method to detect this attack before it leads to failure of the controller. The proposed combined anomaly detection method, which is called Entropy-KL-ML, uses entropy along with KL-divergence and ensemble learning to detect any uncertainty in incoming packets within time slots. KL-divergence and ML classifiers make the detection more accurate. We also present a new method for selecting features based on grouping the features that reduces the computational overhead of the controller. With an anomaly detection method in SDN, it is essential to provide a balance between overhead, accuracy, and processing time. Through a real-world data set and some anomaly detectors, we demonstrate that the Entropy-KL-ML method detects anomalies with greater accuracy and fewer overheads.
引用
收藏
页码:4458 / 4467
页数:10
相关论文
共 38 条
[1]   A hybrid entropy-based DoS attacks detection system for software defined networks (SDN): A proposed trust mechanism [J].
AbdelAzim, Nada M. ;
Fahmy, Sherif F. ;
Sobh, Mohammed Ali ;
Eldin, Ayman M. Bahaa .
EGYPTIAN INFORMATICS JOURNAL, 2021, 22 (01) :85-90
[2]   Identification of Distributed Denial of Services Anomalies by Using Combination of Entropy and Sequential Probabilities Ratio Test Methods [J].
Ali, Basheer Husham ;
Sulaiman, Nasri ;
Al-Haddad, Syed Abdul Rahman ;
Atan, Rodziah ;
Hassan, Siti Lailatul Mohd ;
Alghrairi, Mokhalad .
SENSORS, 2021, 21 (19)
[3]  
Ashodia Namita, 2022, 2022 International Conference on Electronics and Renewable Systems (ICEARS), P1322, DOI 10.1109/ICEARS53579.2022.9751879
[4]   An Entropy-Based Network Anomaly Detection Method [J].
Berezinski, Przemyslaw ;
Jasiul, Bartosz ;
Szpyrka, Marcin .
ENTROPY, 2015, 17 (04) :2367-2408
[5]   Entropy-based DoS Attack identification in SDN [J].
Carvalho, Ranyelson N. ;
Bordim, Jacir L. ;
Alchieri, Eduardo A. P. .
2019 IEEE INTERNATIONAL PARALLEL AND DISTRIBUTED PROCESSING SYMPOSIUM WORKSHOPS (IPDPSW), 2019, :627-634
[6]   A Survey of Machine Learning Methods for DDoS Threats Detection Against SDN [J].
Chetouane, Ameni ;
Karoui, Kamel .
DISTRIBUTED COMPUTING FOR EMERGING SMART NETWORKS, 2022, :99-127
[7]  
Dang TT, 2015, 2015 IEEE INTERNATIONAL CONFERENCE ON DIGITAL SIGNAL PROCESSING (DSP), P507, DOI 10.1109/ICDSP.2015.7251924
[8]   On-the-fly (D)DoS attack mitigation in SDN using Deep Neural Network-based rate [J].
El Kamel, Ali ;
Eltaief, Hamdi ;
Youssef, Habib .
COMPUTER COMMUNICATIONS, 2022, 182 :153-169
[9]  
Faiz M. N., 2022, J. Inf. Telecommun. Eng., V5, P305, DOI [10.31289/jite.v5i2.6112, DOI 10.31289/JITE.V5I2.6112]
[10]   Detection and Mitigation of DoS and DDoS Attacks in IoT-Based Stateful SDN: An Experimental Approach [J].
Galeano-Brajones, Jesus ;
Carmona-Murillo, Javier ;
Valenzuela-Valdes, Juan F. ;
Luna-Valero, Francisco .
SENSORS, 2020, 20 (03)