Lightweight IPS for Port Scan in Openflow SDN networks

被引:0
|
作者
Neu, Charles V. [1 ]
Tatsch, Cassio G. [3 ]
Lunardi, Roben C. [1 ,2 ]
Michelin, Regio A. [1 ,2 ]
Orozco, Alex M. S. [1 ,4 ]
Zorzo, Avelino F. [1 ]
机构
[1] Pontificia Univ Catolica Rio Grande do Sul, Porto Alegre, RS, Brazil
[2] IFRS, Sao Paulo, Brazil
[3] Univ Santa Cruz do Sul, Santa Cruz do Sul, RS, Brazil
[4] IFSul, Pelotas, RS, Brazil
关键词
IPS; OpenFlow; SDN; Port Scan; Lightweight;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Security has been one of the major concerns for the computer network community due to resource abuse and malicious flows intrusion. Before a network or a system is attacked, a port scan is typically performed to discover vulnerabilities, like open ports, which may be used to access and control them. Several studies have addressed Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS) methods for detecting malicious activities, based on received flows or packet data analysis. However, those methods lead to an increase in switching latency, due to the need to analyze flows or packets before routing them. This may also increase network overhead when flows or packets are duplicated to be parsed by an external IDS. On the one hand, an IDS/IPS may be a bottleneck on the network and may not be useful. On the other hand, the new paradigm called Software Defined Networking (SDN) and the OpenFlow protocol provide some statistical information about the network that may be used for detecting malicious activities. Hence, this work presents a new port scan IPS for SDN based on the OpenFlow switch counters data. A non-intrusive and lightweight method was developed and implemented, with low network overhead, and low memory and processing power consumption. The results showed that our method is effective on detecting and preventing port scan attacks.
引用
收藏
页数:6
相关论文
共 50 条
  • [1] SDN and OpenFlow for Converged Access/Aggregation Networks
    Woesner, Hagen
    Fritzsche, Daniel
    2013 OPTICAL FIBER COMMUNICATION CONFERENCE AND EXPOSITION AND THE NATIONAL FIBER OPTIC ENGINEERS CONFERENCE (OFC/NFOEC), 2013,
  • [2] An optimisation framework for monitoring of SDN/OpenFlow networks
    Valdivieso Caraguay, Angel Leonardo
    Puente Fernandez, Jesus Antonio
    Garcia Villalba, Luis Javier
    INTERNATIONAL JOURNAL OF AD HOC AND UBIQUITOUS COMPUTING, 2017, 26 (04) : 263 - 273
  • [3] A Design of Port Scan Detection Method Based on the Characteristics of Packet-In Messages in OpenFlow Networks
    Ono, Daichi
    Izumi, Satoru
    Abe, Toru
    Suganuma, Takuo
    APNOMS 2020: 2020 21ST ASIA-PACIFIC NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM (APNOMS), 2020, : 120 - 125
  • [4] A critical review of OpenFlow/SDN-based networks
    de Almeida Amazonas, Jose Roberto
    Santos-Boada, German
    Sole-Pareta, Josep
    2014 16TH INTERNATIONAL CONFERENCE ON TRANSPARENT OPTICAL NETWORKS (ICTON), 2014,
  • [5] Cloud Orchestration with SDN/OpenFlow in Carrier Transport Networks
    Autenrieth, Achim
    Elbers, Joerg-Peter
    Kaczmarek, Pawel
    Kostecki, Pawel
    2013 15TH INTERNATIONAL CONFERENCE ON TRANSPARENT OPTICAL NETWORKS (ICTON 2013), 2013,
  • [6] Denial-of-Service Attacks in OpenFlow SDN Networks
    Kandoi, Rajat
    Antikainen, Markku
    PROCEEDINGS OF THE 2015 IFIP/IEEE INTERNATIONAL SYMPOSIUM ON INTEGRATED NETWORK MANAGEMENT (IM), 2015, : 1322 - 1326
  • [7] A roadmap for traffic engineering in SDN-OpenFlow networks
    Akyildiz, Ian F.
    Lee, Ahyoung
    Wang, Pu
    Luo, Min
    Chou, Wu
    COMPUTER NETWORKS, 2014, 71 : 1 - 30
  • [8] A proposal of port scan detection method based on Packet-In Messages in OpenFlow networks and its evaluation
    Ono, Daichi
    Guillen, Luis
    Izumi, Satoru
    Abe, Toru
    Suganuma, Takuo
    INTERNATIONAL JOURNAL OF NETWORK MANAGEMENT, 2021, 31 (06)
  • [9] A proposal of port scan detection method based on Packet-In Messages in OpenFlow networks and its evaluation
    Ono, Daichi
    Guillen, Luis
    Izumi, Satoru
    Abe, Toru
    Suganuma, Takuo
    International Journal of Network Management, 31 (06):
  • [10] IPS architecture for IoT networks overlapped in SDN
    Goncalves, Daniel G., V
    de Caldas Filho, Francisco L.
    Martins, Lucas M. C. E.
    Kfouri, Guilherme de O.
    Dutra, Bruno, V
    Albuquerque, Robson de O.
    de Sousa Jr, Rafael T.
    2019 WORKSHOP ON COMMUNICATION NETWORKS AND POWER SYSTEMS (WCNPS), 2019,