Lightweight IPS for Port Scan in Openflow SDN networks

被引:0
|
作者
Neu, Charles V. [1 ]
Tatsch, Cassio G. [3 ]
Lunardi, Roben C. [1 ,2 ]
Michelin, Regio A. [1 ,2 ]
Orozco, Alex M. S. [1 ,4 ]
Zorzo, Avelino F. [1 ]
机构
[1] Pontificia Univ Catolica Rio Grande do Sul, Porto Alegre, RS, Brazil
[2] IFRS, Sao Paulo, Brazil
[3] Univ Santa Cruz do Sul, Santa Cruz do Sul, RS, Brazil
[4] IFSul, Pelotas, RS, Brazil
关键词
IPS; OpenFlow; SDN; Port Scan; Lightweight;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Security has been one of the major concerns for the computer network community due to resource abuse and malicious flows intrusion. Before a network or a system is attacked, a port scan is typically performed to discover vulnerabilities, like open ports, which may be used to access and control them. Several studies have addressed Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS) methods for detecting malicious activities, based on received flows or packet data analysis. However, those methods lead to an increase in switching latency, due to the need to analyze flows or packets before routing them. This may also increase network overhead when flows or packets are duplicated to be parsed by an external IDS. On the one hand, an IDS/IPS may be a bottleneck on the network and may not be useful. On the other hand, the new paradigm called Software Defined Networking (SDN) and the OpenFlow protocol provide some statistical information about the network that may be used for detecting malicious activities. Hence, this work presents a new port scan IPS for SDN based on the OpenFlow switch counters data. A non-intrusive and lightweight method was developed and implemented, with low network overhead, and low memory and processing power consumption. The results showed that our method is effective on detecting and preventing port scan attacks.
引用
收藏
页数:6
相关论文
共 50 条
  • [21] Host Discovery Solution: An Enhancement of Topology Discovery in OpenFlow based SDN Networks
    Manzanares-Lopez, Pilar
    Pedro Munoz-Gea, Juan
    Manuel Delicado-Martinez, Francisco
    Malgosa-Sanahuja, Josemaria
    Flores de la Cruz, Adrian
    DCNET: PROCEEDINGS OF THE 13TH INTERNATIONAL JOINT CONFERENCE ON E-BUSINESS AND TELECOMMUNICATIONS - VOL. 1, 2016, : 80 - 88
  • [22] Design of a Network Scan Defense Method by Combining an SDN-based MTD and IPS
    Chiba, Shoya
    Guillen, Luis
    Izumi, Satoru
    Abe, Toru
    Suganuma, Takuo
    2021 22ND ASIA-PACIFIC NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM (APNOMS), 2021, : 273 - 278
  • [23] A trust-aware openflow switching framework for software defined networks (SDN)
    Karmakar, Kallol Krishna
    Varadharajan, Vijay
    Hitchens, Michael
    Tupakula, Uday
    Sariputra, Prajna
    COMPUTER NETWORKS, 2023, 237
  • [24] DeepContext: An OpenFlow-Compatible, Host-Based SDN for Enterprise Networks
    Najd, Mohamed E.
    Shue, Craig A.
    2017 IEEE 42ND CONFERENCE ON LOCAL COMPUTER NETWORKS (LCN), 2017, : 112 - 119
  • [25] SDN/OpenFlow测试技术探讨
    顾彬
    电信网技术, 2013, (03) : 69 - 75
  • [26] SDN and OpenFlow Evolution: A Standards Perspective
    Tourrilhes, Jean
    Sharma, Puneet
    Banerjee, Sujata
    Pettit, Justin
    COMPUTER, 2014, 47 (11) : 22 - 29
  • [27] SDN Interactive Manager: An OpenFlow-Based SDN Manager
    Isolani, Pedro Heleno
    Wickboldt, Juliano Araujo
    Both, Cristiano Bonato
    Rochol, Juergen
    Granville, Lisandro Zambenedetti
    PROCEEDINGS OF THE 2015 IFIP/IEEE INTERNATIONAL SYMPOSIUM ON INTEGRATED NETWORK MANAGEMENT (IM), 2015, : 1157 - 1158
  • [28] Firewall as a service in SDN OpenFlow network
    Arins, Andis
    PROCEEDINGS OF THE 2015 IEEE 3RD WORKSHOP ON ADVANCES IN INFORMATION, ELECTRONIC AND ELECTRICAL ENGINEERING (AIEEE 2015), 2015,
  • [29] SDN Architecture to prevent attacks with OpenFlow
    Flauzac, Olivier
    Robledo, Erick Gallegos
    Gonzalez, Carlos
    Mauhourat, Fabien
    Nolot, Florent
    2020 8TH INTERNATIONAL CONFERENCE ON WIRELESS NETWORKS AND MOBILE COMMUNICATIONS (WINCOM 2020), 2020, : 40 - 45
  • [30] On Integrating Lightweight Encryption in Reconfigurable Scan Networks
    Thiemann, Benjamin
    Feiten, Linus
    Raiola, Pascal
    Becker, Bernd
    Sauer, Matthias
    2019 IEEE EUROPEAN TEST SYMPOSIUM (ETS), 2019,