Cyber-AnDe: Cybersecurity Framework With Adaptive Distributed Sampling for Anomaly Detection on SDNs

被引:0
|
作者
Niknami, Nadia [1 ]
Srinivasan, Avinash [2 ]
Wu, Jie [1 ]
机构
[1] Temple Univ, Ctr Networked Comp, Philadelphia, PA 19140 USA
[2] US Naval Acad, Dept Cyber Sci, Annapolis, MD 21402 USA
关键词
Control systems; Accuracy; Monitoring; Anomaly detection; Telecommunication traffic; Sampling methods; Intrusion detection; Adaptive sampling; anomaly detection; attack; cybersecurity; intrusion detection; load balancing; network monitoring; sampling rate; software-defined networks; SOFTWARE; CONTROLLER;
D O I
10.1109/TIFS.2024.3468632
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
By decoupling the control plane and data plane in the software-defined network (SDN), the controller gains a comprehensive global view of the network. The SDN controller samples traffic from all switches to effectively manage data plane traffic. The sampling rate of flow traffic significantly impacts the accuracy of the controller's decisions. While increasing the sampling rate is desirable for improved detection accuracy, it also escalates resource consumption on both switches and the controller. Hence, it is crucial to carefully manage sampling on switches to fine-tune anomaly detection accuracy. Existing flow sampling solutions often struggle to strike a balance between detection accuracy, sampling rate, and overhead. To address this challenge, we propose a robust cybersecurity framework for anomaly detection on SDNs through traffic flow inspection. Our proposed framework, Cyber-AnDe, integrates adaptive distributed sampling (ADS) with a Reinforcement Learning (RL) agent to enhance anomaly detection accuracy while minimizing the increase in controller overhead. In our framework, the controller leverages information gathered from each sampled traffic flow to determine whether the flow's state is malicious, suspicious, or benign based on underlying anomaly detection algorithms. Once the flow state is determined, the controller takes the appropriate action with the help of the RL agent. Through extensive simulations and SDN test-bed experiments, we confirm a significant improvement of up to 93% in network traffic-based anomaly detection compared to existing solutions.
引用
收藏
页码:9245 / 9257
页数:13
相关论文
共 50 条
  • [41] A Spiking One-Class Anomaly Detection Framework for Cyber-Security on Industrial Control Systems
    Demertzis, Konstantinos
    Iliadis, Lazaros
    Spartalis, Stefanos
    ENGINEERING APPLICATIONS OF NEURAL NETWORKS, EANN 2017, 2017, 744 : 122 - 134
  • [42] Cy-Phy ADS: Cyber-Physical Anomaly Detection Framework for EV Charging Systems
    Mavikumbure, Harindra S.
    Cobilean, Victor
    Wickramasinghe, Chathurika S.
    Varghese, Benny J.
    Carlson, Richard B.
    Rieger, Craig
    Pennington, Timothy
    Manic, Milos
    IEEE TRANSACTIONS ON TRANSPORTATION ELECTRIFICATION, 2024, 10 (04): : 9904 - 9917
  • [43] Adaptive-Correlation-Aware Unsupervised Deep Learning for Anomaly Detection in Cyber-Physical Systems
    Xi, Liang
    Miao, Dehua
    Li, Menghan
    Wang, Ruidong
    Liu, Han
    Huang, Xunhua
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2024, 21 (04) : 2888 - 2899
  • [44] Deep-Learning Based Detection for Cyber-Attacks in IoT Networks: A Distributed Attack Detection Framework
    Olivia Jullian
    Beatriz Otero
    Eva Rodriguez
    Norma Gutierrez
    Héctor Antona
    Ramon Canal
    Journal of Network and Systems Management, 2023, 31
  • [45] Deep-Learning Based Detection for Cyber-Attacks in IoT Networks: A Distributed Attack Detection Framework
    Jullian, Olivia
    Otero, Beatriz
    Rodriguez, Eva
    Gutierrez, Norma
    Antona, Hector
    Canal, Ramon
    JOURNAL OF NETWORK AND SYSTEMS MANAGEMENT, 2023, 31 (02)
  • [46] Random sampling statistical analysis for adaptive target-scale-invariant hyperspectral anomaly detection
    Romano, Joao M.
    Rosario, Dalton
    ALGORITHMS AND TECHNOLOGIES FOR MULTISPECTRAL, HYPERSPECTRAL, AND ULTRASPECTRAL IMAGERY XIII, 2007, 6565
  • [47] An Adaptive Framework for Anomaly Detection in Time-Series Audio-Visual Data
    Kumari, Pratibha
    Saini, Mukesh
    IEEE ACCESS, 2022, 10 : 36188 - 36199
  • [48] Efficient Distributed Preprocessing Model for Machine Learning-Based Anomaly Detection over Large-Scale Cybersecurity Datasets
    Larriva-Novo, Xavier
    Vega-Barbas, Mario
    Villagra, Victor A.
    Rivera, Diego
    Alvarez-Campana, Manuel
    Berrocal, Julio
    APPLIED SCIENCES-BASEL, 2020, 10 (10):
  • [49] Parallel distributed computing based wireless sensor network anomaly data detection in IoT framework
    Li, Qian
    Sun, Ruizhi
    Wu, Huiling
    Zhang, Qianqian
    COGNITIVE SYSTEMS RESEARCH, 2018, 52 : 342 - 350
  • [50] Real-Time Adaptive and Lightweight Anomaly Detection Based on a Chaotic System in Cyber-Physical Systems
    Park, Jung Kyu
    Baek, Youngmi
    ELECTRONICS, 2025, 14 (03):