Cyber-AnDe: Cybersecurity Framework With Adaptive Distributed Sampling for Anomaly Detection on SDNs

被引:0
|
作者
Niknami, Nadia [1 ]
Srinivasan, Avinash [2 ]
Wu, Jie [1 ]
机构
[1] Temple Univ, Ctr Networked Comp, Philadelphia, PA 19140 USA
[2] US Naval Acad, Dept Cyber Sci, Annapolis, MD 21402 USA
关键词
Control systems; Accuracy; Monitoring; Anomaly detection; Telecommunication traffic; Sampling methods; Intrusion detection; Adaptive sampling; anomaly detection; attack; cybersecurity; intrusion detection; load balancing; network monitoring; sampling rate; software-defined networks; SOFTWARE; CONTROLLER;
D O I
10.1109/TIFS.2024.3468632
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
By decoupling the control plane and data plane in the software-defined network (SDN), the controller gains a comprehensive global view of the network. The SDN controller samples traffic from all switches to effectively manage data plane traffic. The sampling rate of flow traffic significantly impacts the accuracy of the controller's decisions. While increasing the sampling rate is desirable for improved detection accuracy, it also escalates resource consumption on both switches and the controller. Hence, it is crucial to carefully manage sampling on switches to fine-tune anomaly detection accuracy. Existing flow sampling solutions often struggle to strike a balance between detection accuracy, sampling rate, and overhead. To address this challenge, we propose a robust cybersecurity framework for anomaly detection on SDNs through traffic flow inspection. Our proposed framework, Cyber-AnDe, integrates adaptive distributed sampling (ADS) with a Reinforcement Learning (RL) agent to enhance anomaly detection accuracy while minimizing the increase in controller overhead. In our framework, the controller leverages information gathered from each sampled traffic flow to determine whether the flow's state is malicious, suspicious, or benign based on underlying anomaly detection algorithms. Once the flow state is determined, the controller takes the appropriate action with the help of the RL agent. Through extensive simulations and SDN test-bed experiments, we confirm a significant improvement of up to 93% in network traffic-based anomaly detection compared to existing solutions.
引用
收藏
页码:9245 / 9257
页数:13
相关论文
共 50 条
  • [31] Adaptive learning anomaly detection and classification model for cyber and physical threats in industrial control systems
    Ahmadi-Assalemi, Gabriela
    Al-Khateeb, Haider
    Benson, Vladlena
    Adamyk, Bogdan
    Ammi, Meryem
    IET CYBER-PHYSICAL SYSTEMS: THEORY & APPLICATIONS, 2025, 10 (01)
  • [32] Feature-based control and information framework for adaptive and distributed manufacturing in cyber physical systems
    Adamson, Goran
    Wang, Lihui
    Moore, Philip
    JOURNAL OF MANUFACTURING SYSTEMS, 2017, 43 : 305 - 315
  • [33] Adaptive flow sampling algorithm based on sampled packets and force sampling Threshold S towards anomaly detection
    Yi, Peng
    Qian, Kun
    Huang, Wan-Wei
    Wang, Jing
    Zhang, Zhen
    Dianzi Yu Xinxi Xuebao/Journal of Electronics and Information Technology, 2015, 37 (07): : 1606 - 1611
  • [34] An Adaptive Sampling Strategy for Real-Time Anomaly Detection with Unmanned Sensing Vehicles
    Jiang, Yue
    Gomez, Ana Maria Estrada
    TECHNOMETRICS, 2024, 66 (03) : 438 - 454
  • [35] Towards a conceptual framework for AI-driven anomaly detection in smart city IoT networks for enhanced cybersecurity
    Zeng, Heng
    Yunis, Manal
    Khalil, Ayman
    Mirza, Nawazish
    JOURNAL OF INNOVATION & KNOWLEDGE, 2024, 9 (04):
  • [36] A hybrid behavior- and Bayesian network-based framework for cyber-physical anomaly detection
    Faramondi, Luca
    Flammini, Francesco
    Guarino, Simone
    Setola, Roberto
    COMPUTERS & ELECTRICAL ENGINEERING, 2023, 112
  • [37] Towards Zero-Shot Flow-Based Cyber-Security Anomaly Detection Framework
    Komisarek, Mikolaj
    Kozik, Rafal
    Pawlicki, Marek
    Choras, Michal
    APPLIED SCIENCES-BASEL, 2022, 12 (19):
  • [38] DILAF: A framework for distributed analysis of large-scale system logs for anomaly detection
    Astekin, Merve
    Zengin, Harun
    Sozer, Hasan
    SOFTWARE-PRACTICE & EXPERIENCE, 2019, 49 (02): : 153 - 170
  • [39] A distributed Framework for Supporting Adaptive Ensemble-based Intrusion Detection
    Cuzzocrea, Alfredo
    Folino, Gianluigi
    Sabatino, Pietro
    PROCEEDINGS 2015 IEEE INTERNATIONAL CONFERENCE ON BIG DATA, 2015, : 1910 - 1916
  • [40] Online anomaly detection for multi-source VMware using a distributed streaming framework
    Solaimani, Mohiuddin
    Iftekhar, Mohammed
    Khan, Latifur
    Thuraisingham, Bhavani
    Ingram, Joe
    Seker, Sadi Evren
    SOFTWARE-PRACTICE & EXPERIENCE, 2016, 46 (11): : 1479 - 1497