کد مقاله کد نشریه سال انتشار مقاله انگلیسی نسخه تمام متن
4956057 1444380 2017 22 صفحه PDF دانلود رایگان
عنوان انگلیسی مقاله ISI
Identifying cyber-attacks on software defined networks: An inference-based intrusion detection approach
ترجمه فارسی عنوان
شناسایی حملات سایبری به شبکه های تعریف شده توسط نرم افزار: یک روش تشخیص نفوذ مبتنی بر استنتاج
کلمات کلیدی
نرم افزار شبکه های تعریف شده، امنیت اطلاعات، تشخیص نفوذ، معدن گراف، انکار سرویس حملات، معماری امنیت،
موضوعات مرتبط
مهندسی و علوم پایه مهندسی کامپیوتر شبکه های کامپیوتری و ارتباطات
چکیده انگلیسی
Software Defined Networking is an emerging architecture which focuses on the role of software to manage computer networks. Software Defined Networks (SDNs) introduce several mechanisms to detect specific types of attacks such as Denial of Service (DoS). Nevertheless, they are vulnerable to similar attacks that occur in traditional networks, such as the attacks that target control and data plane. Several techniques are proposed to handle the security vulnerabilities in SDNs. However, it is fairly challenging to create attack signatures, scenarios, or even intrusion detection rules that are applicable to dynamic environments such SDNs. This paper introduces a new approach to identify attacks on SDNs that uses: (1) similarity with existing attacks that target traditional networks, (2) an inference mechanism to avoid false positives and negatives during the prediction process, and (3) a packet aggregation technique which aims at creating attack signatures and use them to predict attacks on SDNs. We validated our approach on two datasets and showed that it yields promising results.
ناشر
Database: Elsevier - ScienceDirect (ساینس دایرکت)
Journal: Journal of Network and Computer Applications - Volume 80, 15 February 2017, Pages 152-164
نویسندگان
, ,