CTMBIDS: convolutional Tsetlin machine-based intrusion detection system for DDoS attacks in an SDN environment

被引:0
|
作者
Rasoul Jafari Gohari [1 ]
Laya Aliahmadipour [1 ]
Marjan Kuchaki Rafsanjani [1 ]
机构
[1] Shahid Bahonar University of Kerman,Department of Computer Science, Faculty of Mathematics and Computer
关键词
Software defined network; Intrusion detection system; Distributed denial of service; Convolutional Tsetlin machine;
D O I
10.1007/s00521-025-10976-2
中图分类号
学科分类号
摘要
Software Defined Networks (SDN) face many security challenges today. A great deal of research has been done within the field of Intrusion Detection Systems (IDS) in these networks. Yet, numerous approaches still rely on deep learning algorithms, but these algorithms suffer from complexity in implementation, the need for high processing power, and high memory consumption. In addition to security issues, firstly, the number of datasets that are based on SDN protocols are very small. Secondly, the ones that are available encompass a variety of attacks in the network and do not focus on a single attack. For this reason, to introduce an SDN-based IDS with a focus on Distributed Denial of Service (DDoS) attacks, it is necessary to generate a DDoS-oriented dataset whose features can train a high-quality IDS. In this work, in order to address two important challenges in SDNs, in the first step, we generate three DDoS attack datasets based on three common and different network topologies. Then, in the second step, using the Convolutional Tsetlin Machine (CTM) algorithm, we introduce a lightweight IDS for DDoS attack dubbed "CTMBIDS," with which we implement an anomaly-based IDS. The lightweight nature of the CTMBIDS stems from its low memory consumption and also its interpretability compared to the existing complex deep learning models. The low usage of system resources for the CTMBIDS makes it an ideal choice for an optimal software that consumes the SDN controller’s least amount of memory. Also, in order to ascertain the quality of the generated datasets, we compare the empirical results of our work with the DDoS attacks of the KDDCup99 benchmark dataset as well. Since the main focus of this work is on a lightweight IDS, the results of this work show that the CTMBIDS performs much more efficiently than traditional and deep learning based machine learning algorithms. Furthermore, the results also show that in most datasets, the proposed method has relatively equal or better accuracy and also consumes much less memory than the existing methods.
引用
收藏
页码:6795 / 6818
页数:23
相关论文
共 50 条
  • [1] SDN-Based Intrusion Detection System for Early Detection and Mitigation of DDoS Attacks
    Manso, Pedro
    Moura, Jose
    Serrao, Carlos
    INFORMATION, 2019, 10 (03)
  • [2] Detecting DDoS Attacks through AI driven SDN Intrusion Detection System
    Salatino, Francesco
    Spina, Mattia Giovanni
    Tropea, Mauro
    De Rango, Floriano
    2024 IEEE 21ST CONSUMER COMMUNICATIONS & NETWORKING CONFERENCE, CCNC, 2024, : 990 - 993
  • [3] SDN-Based Network Intrusion Detection as DDoS defense system for Virtualization Environment
    Usman, Saifudin
    Winarno, Idris
    Sudarsono, Amang
    EMITTER-INTERNATIONAL JOURNAL OF ENGINEERING TECHNOLOGY, 2021, 9 (02) : 252 - 267
  • [4] DNS Amplification Based DDoS Attacks in SDN Environment: Detection and Mitigation
    Gupta, Vishal
    Kochar, Amrit
    Saharan, Shail
    Kulshrestha, Rakhee
    2019 IEEE 4TH INTERNATIONAL CONFERENCE ON COMPUTER AND COMMUNICATION SYSTEMS (ICCCS 2019), 2019, : 473 - 478
  • [5] Virtual Machine-based Intrusion Detection System Framework in Cloud Computing Environment
    Wang, Huaibin
    Zhou, Haiyun
    Wang, Chundong
    JOURNAL OF COMPUTERS, 2012, 7 (10) : 2397 - 2403
  • [6] K-DDoS-SDN: A distributed DDoS attacks detection approach for protecting SDN environment
    Kaur, Amandeep
    Krishna, C. Rama
    Patil, Nilesh Vishwasrao
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2024, 36 (03):
  • [7] Hybrid Intrusion Detection System for DDoS Attacks
    Cepheli, Ozge
    Buyukcorak, Saliha
    Kurt, Gunes Karabulut
    JOURNAL OF ELECTRICAL AND COMPUTER ENGINEERING, 2016, 2016
  • [8] A Collaborative Intrusion Detection System against DDoS for SDN
    Chen, Xiaofan
    Yu, Shunzheng
    IEICE TRANSACTIONS ON INFORMATION AND SYSTEMS, 2016, E99D (09) : 2395 - 2399
  • [9] DDoS Attacks Detection and Mitigation in SDN using Machine Learning
    Rahman, Obaid
    Quraishi, Mohammad Ali Gauhar
    Lung, Chung-Horng
    2019 IEEE WORLD CONGRESS ON SERVICES (IEEE SERVICES 2019), 2019, : 184 - 189
  • [10] VNIDS: A Virtual Machine-based Network Intrusion Detection System
    Zhao, Feng
    Yang, Weiping
    Jin, Hai
    Wu, Song
    2008 2ND INTERNATIONAL CONFERENCE ON ANTI-COUNTERFEITING, SECURITY AND IDENTIFICATION, 2008, : 254 - 259