Detecting anomalies efficiently in SDN using adaptive mechanism

被引:9
作者
Garg, Gagandeep [1 ]
Garg, Roopali [1 ]
机构
[1] Panjab Univ, UIET, Dept IT, Chandigarh, India
来源
2015 5TH INTERNATIONAL CONFERENCE ON ADVANCED COMPUTING & COMMUNICATION TECHNOLOGIES ACCT 2015 | 2015年
关键词
Anomaly detection; SDN; flow-counting; traffic-aggregation; Network traffic monitoring; Network management;
D O I
10.1109/ACCT.2015.98
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Monitoring and measurement of network traffic flows in SDN is key requirement for maintaining the integrity of our data in network. It plays a vital role in management task of SDN controller for controlling the traffic. Anomaly detection considered as one of the important issues while monitoring the traffic. More efficiently we detect the anomalies, easier it will be for us, to manage the traffic. However we have to consider the workload, response time and overhead on network while applying the network monitoring policies, so that our network perform with similar efficiency. To reduce the overhead, it is required to perform analysis on certain portion of traffic instead of analyzing each and every packet in the network. This paper presents an adaptive mechanism for dynamically updating the policies for aggregation of flow entries and anomaly detection, so that monitoring overhead can be reduced and anomalies can be detected with greater accuracy. In previous work, rules for expansion and contraction of aggregation policies according to adaptive behavior are defined. This paper represents a work towards reducing the complexity of dynamic algorithm for updating policies of flow counting rules for anomaly detection.
引用
收藏
页码:367 / 370
页数:4
相关论文
共 11 条
  • [1] Banford P, 2002, ACM P SIGCOMM IMW 02, P71
  • [2] Garg R, 2014, INT J INNOV RES COMP, V2, P6519
  • [3] Giotis K, 2013, P EWSDN BUD HUNG SEP
  • [4] Mining anomalies using traffic feature distributions
    Lakhina, A
    Crovella, M
    Diot, C
    [J]. ACM SIGCOMM COMPUTER COMMUNICATION REVIEW, 2005, 35 (04) : 217 - 228
  • [5] Impact of packet sampling on portscan detection
    Mai, Jianning
    Sridharan, Ashwin
    Chuah, Chen-Nee
    Zang, Hui
    Ye, Tao
    [J]. IEEE JOURNAL ON SELECTED AREAS IN COMMUNICATIONS, 2006, 24 (12) : 2285 - 2298
  • [6] Moshref Masoud., 2013, HOTSDN, P73, DOI DOI 10.1145/2491185.2491196
  • [7] Narayana Srinivas., 2014, P 3 WORKSHOP HOT TOP, P181
  • [8] Reich J., 2013, LOGIN USENIX MAG, V38, P40
  • [9] Shin S., 2013, Proceedings of the Second ACM SIGCOMM Workshop on Hot Topics in Software Defined Networking, P165, DOI [DOI 10.1145/2491185.2491220, 10.1145/2491185.2491220]
  • [10] Zhang Y, 2013, PROCEEDINGS OF THE 2013 ACM INTERNATIONAL CONFERENCE ON EMERGING NETWORKING EXPERIMENTS AND TECHNOLOGIES (CONEXT '13), P25