Scalable and Dynamic Network Intrusion Detection and Prevention System

被引:2
作者
Mahrach, Safaa [1 ]
Mjihil, Oussama [1 ]
Haqiq, Abdelkrim [1 ,2 ]
机构
[1] Hassan 1st Univ, Comp Networks Mobil & Modeling Lab, FST, Settat, Morocco
[2] E NGN Res Grp, Rabat, Morocco
来源
INNOVATIONS IN BIO-INSPIRED COMPUTING AND APPLICATIONS, IBICA 2017 | 2018年 / 735卷
关键词
SDN; Network security; DDOS; IDS; IPS; P4; language; SECURITY; SDN;
D O I
10.1007/978-3-319-76354-5_29
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Network Intrusion Detection and Prevention Systems (NIDPS) are widely used to detect and thwart malicious activities and attacks. However, the existing NIDPS are monolithic/centralized, and hence they are very limited in terms of scalability and responsiveness. In this work, we address how to mitigate SYN Flooding attacks that can occur in the management network (OpenFlow) as well as in the production network taking into account the network scalability. Our suggested framework is a distributed and dynamic NIDPS that uses the Programming Protocol independent Packet Processors (P4) to process the network packets at the switch level and perform two main functions. First, it detects the SYN flooding attacks based on the SYN packets' rate and threshold. Secondly, our system uses a reviewed way to activate the SYN cookies in order to block/drop illegitimate packets. Our framework takes advantage of the switch programmability (i.e., using P4 language), distributed packet processing, and centralized Software Defined Networking (SDN) control, to provide an efficient and extensible NIDPS.
引用
收藏
页码:318 / 328
页数:11
相关论文
共 22 条
[1]  
[Anonymous], 2016, NDSS
[2]  
[Anonymous], P IEEE C COMP COMM I
[3]  
[Anonymous], 2007, NIST SPECIAL PUBLICA
[4]  
Benton K., 2013, P 2 ACM SIGCOMM WORK, P151, DOI [DOI 10.1145/2491185.2491222, 10.1145/2491185.2491222]
[5]  
Bianchi G, 2014, ACM SIGCOMM COMP COM, V44, P45
[6]   Programming Protocol-Independent Packet Processors [J].
Bosshart, Pat ;
Daly, Dan ;
Gibb, Glen ;
Izzard, Martin ;
McKeown, Nick ;
Rexford, Jennifer ;
Schlesinger, Cole ;
Talayco, Dan ;
Vahdat, Amin ;
Varghese, George ;
Walker, David .
ACM SIGCOMM COMPUTER COMMUNICATION REVIEW, 2014, 44 (03) :87-95
[7]   A Survey on the Security of Stateful SDN Data Planes [J].
Dargahi, Tooska ;
Caponi, Alberto ;
Ambrosin, Moreno ;
Bianchi, Giuseppe ;
Conti, Mauro .
IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2017, 19 (03) :1701-1725
[8]  
Echevarria J.J., SOFTW PRACT EXP
[9]  
Fontes S.M., 2006, US Patent, Patent No. [7,058,718, 7058718]
[10]   OpenFlow: Enabling innovation in campus networks [J].
McKeown, Nick ;
Anderson, Tom ;
Balakrishnan, Hari ;
Parulkar, Guru ;
Peterson, Larry ;
Rexford, Jennifer ;
Shenker, Scott ;
Turner, Jonathan .
ACM SIGCOMM COMPUTER COMMUNICATION REVIEW, 2008, 38 (02) :69-74