Cyber-AnDe: Cybersecurity Framework With Adaptive Distributed Sampling for Anomaly Detection on SDNs

被引:0
|
作者
Niknami, Nadia [1 ]
Srinivasan, Avinash [2 ]
Wu, Jie [1 ]
机构
[1] Temple Univ, Ctr Networked Comp, Philadelphia, PA 19140 USA
[2] US Naval Acad, Dept Cyber Sci, Annapolis, MD 21402 USA
关键词
Control systems; Accuracy; Monitoring; Anomaly detection; Telecommunication traffic; Sampling methods; Intrusion detection; Adaptive sampling; anomaly detection; attack; cybersecurity; intrusion detection; load balancing; network monitoring; sampling rate; software-defined networks; SOFTWARE; CONTROLLER;
D O I
10.1109/TIFS.2024.3468632
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
By decoupling the control plane and data plane in the software-defined network (SDN), the controller gains a comprehensive global view of the network. The SDN controller samples traffic from all switches to effectively manage data plane traffic. The sampling rate of flow traffic significantly impacts the accuracy of the controller's decisions. While increasing the sampling rate is desirable for improved detection accuracy, it also escalates resource consumption on both switches and the controller. Hence, it is crucial to carefully manage sampling on switches to fine-tune anomaly detection accuracy. Existing flow sampling solutions often struggle to strike a balance between detection accuracy, sampling rate, and overhead. To address this challenge, we propose a robust cybersecurity framework for anomaly detection on SDNs through traffic flow inspection. Our proposed framework, Cyber-AnDe, integrates adaptive distributed sampling (ADS) with a Reinforcement Learning (RL) agent to enhance anomaly detection accuracy while minimizing the increase in controller overhead. In our framework, the controller leverages information gathered from each sampled traffic flow to determine whether the flow's state is malicious, suspicious, or benign based on underlying anomaly detection algorithms. Once the flow state is determined, the controller takes the appropriate action with the help of the RL agent. Through extensive simulations and SDN test-bed experiments, we confirm a significant improvement of up to 93% in network traffic-based anomaly detection compared to existing solutions.
引用
收藏
页码:9245 / 9257
页数:13
相关论文
共 50 条
  • [1] An anomaly detection framework for cyber-security data
    Evangelou, Marina
    Adams, Niall M.
    COMPUTERS & SECURITY, 2020, 97
  • [2] Cascaded Anomaly Detection with Coarse Sampling in Distributed Systems
    Badica, Amelia
    Badica, Costin
    Bolanowski, Marek
    Fidanova, Stefka
    Ganzha, Maria
    Harizanov, Stanislav
    Ivanovic, Mirjana
    Lirkov, Ivan
    Paprzycki, Marcin
    Paszkiewicz, Andrzej
    Tomczyk, Kacper
    BIG-DATA-ANALYTICS IN ASTRONOMY, SCIENCE, AND ENGINEERING, BDA 2021, 2022, 13167 : 181 - 200
  • [3] Adaptive Sampling and Quick Anomaly Detection in Large Networks
    Xian, Xiaochen
    Semenov, Alexander
    Hu, Yaodan
    Wang, Andi
    Jin, Yier
    IEEE TRANSACTIONS ON AUTOMATION SCIENCE AND ENGINEERING, 2023, 20 (04) : 2253 - 2267
  • [4] Deception Detection in Cyber Conflicts: A Use Case for the Cybersecurity Strategy Formation Framework
    Chen, Jim Q.
    INTERNATIONAL JOURNAL OF CYBER WARFARE AND TERRORISM, 2016, 6 (03) : 31 - 42
  • [5] Distributed Network Anomaly Detection on an Event Processing Framework
    Pamukchiev, Atanas
    Jouet, Simon
    Pezaros, Dimitrios P.
    2017 14TH IEEE ANNUAL CONSUMER COMMUNICATIONS & NETWORKING CONFERENCE (CCNC), 2017, : 659 - 664
  • [6] An ensemble-based framework for user behaviour anomaly detection and classification for cybersecurity
    Gianluigi Folino
    Carla Otranto Godano
    Francesco Sergio Pisani
    The Journal of Supercomputing, 2023, 79 : 11660 - 11683
  • [7] An ensemble-based framework for user behaviour anomaly detection and classification for cybersecurity
    Folino, Gianluigi
    Godano, Carla Otranto
    Pisani, Francesco Sergio
    JOURNAL OF SUPERCOMPUTING, 2023, 79 (11): : 11660 - 11683
  • [8] Adaptive Sampling Strategy for Accurate and Scalable Anomaly Detection in NGMN
    Hashim, Fazirulhisyam
    Jamalipour, Abbas
    ICSPCS: 2ND INTERNATIONAL CONFERENCE ON SIGNAL PROCESSING AND COMMUNICATION SYSTEMS, PROCEEDINGS, 2008, : 585 - 590
  • [9] Distributed data-centric adaptive sampling for cyber-physical systems
    Lee, Eun Kyung
    Viswanathan, Hariharasudhan
    Pompili, Dario
    ACM Transactions on Autonomous and Adaptive Systems, 2015, 9 (04)
  • [10] A Distributed Trustable Framework for AI-Aided Anomaly Detection
    Nomikos, Nikolaos
    Xylouris, George
    Patsourakis, Gerasimos
    Nikolakakis, Vasileios
    Giannopoulos, Anastasios
    Mandilaris, Charilaos
    Gkonis, Panagiotis
    Skianis, Charalabos
    Trakadas, Panagiotis
    ELECTRONICS, 2025, 14 (03):