Lightweight IPS for Port Scan in Openflow SDN networks

被引:0
|
作者
Neu, Charles V. [1 ]
Tatsch, Cassio G. [3 ]
Lunardi, Roben C. [1 ,2 ]
Michelin, Regio A. [1 ,2 ]
Orozco, Alex M. S. [1 ,4 ]
Zorzo, Avelino F. [1 ]
机构
[1] Pontificia Univ Catolica Rio Grande do Sul, Porto Alegre, RS, Brazil
[2] IFRS, Sao Paulo, Brazil
[3] Univ Santa Cruz do Sul, Santa Cruz do Sul, RS, Brazil
[4] IFSul, Pelotas, RS, Brazil
关键词
IPS; OpenFlow; SDN; Port Scan; Lightweight;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Security has been one of the major concerns for the computer network community due to resource abuse and malicious flows intrusion. Before a network or a system is attacked, a port scan is typically performed to discover vulnerabilities, like open ports, which may be used to access and control them. Several studies have addressed Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS) methods for detecting malicious activities, based on received flows or packet data analysis. However, those methods lead to an increase in switching latency, due to the need to analyze flows or packets before routing them. This may also increase network overhead when flows or packets are duplicated to be parsed by an external IDS. On the one hand, an IDS/IPS may be a bottleneck on the network and may not be useful. On the other hand, the new paradigm called Software Defined Networking (SDN) and the OpenFlow protocol provide some statistical information about the network that may be used for detecting malicious activities. Hence, this work presents a new port scan IPS for SDN based on the OpenFlow switch counters data. A non-intrusive and lightweight method was developed and implemented, with low network overhead, and low memory and processing power consumption. The results showed that our method is effective on detecting and preventing port scan attacks.
引用
收藏
页数:6
相关论文
共 50 条
  • [31] Access Port Protection for Reconfigurable Scan Networks
    Baranowski, Rafal
    Kochte, Michael A.
    Wunderlich, Hans-Joachim
    JOURNAL OF ELECTRONIC TESTING-THEORY AND APPLICATIONS, 2014, 30 (06): : 711 - 723
  • [32] Access Port Protection for Reconfigurable Scan Networks
    Rafal Baranowski
    Michael A. Kochte
    Hans-Joachim Wunderlich
    Journal of Electronic Testing, 2014, 30 : 711 - 723
  • [33] Detecting and mitigating DHCP attacks in OpenFlow-based SDN networks: a comprehensive approach
    Manar Aldaoud
    Dawood Al-Abri
    Ahmed Al Maashri
    Firdous Kausar
    Journal of Computer Virology and Hacking Techniques, 2023, 19 : 597 - 614
  • [34] OpenFlow-compliant Topology Management for SDN-enabled Information Centric Networks
    Petropoulos, George
    Katsaros, Konstantinos V.
    Xezonaki, Maria-Evgenia
    2017 IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATIONS (ISCC), 2017, : 951 - 954
  • [35] Detecting and mitigating DHCP attacks in OpenFlow-based SDN networks: a comprehensive approach
    Aldaoud, Manar
    Al-Abri, Dawood
    Al Maashri, Ahmed
    Kausar, Firdous
    JOURNAL OF COMPUTER VIROLOGY AND HACKING TECHNIQUES, 2023, 19 (04) : 597 - 614
  • [36] An MPTCP-Compatible Load Balancing Solution for Pools of Servers in OpenFlow SDN Networks
    Manzanares-Lopez, Pilar
    Pedro Munoz-Gea, Juan
    Malgosa-Sanahuja, Josemaria
    2019 SIXTH INTERNATIONAL CONFERENCE ON SOFTWARE DEFINED SYSTEMS (SDS), 2019, : 39 - 46
  • [37] SDN Orchestration of OpenFlow and GMPLS Flexi-Grid Networks With a Stateful Hierarchical PCE
    Casellas, Ramon
    Munoz, Rauel
    Martinez, Ricardo
    Vilalta, Ricard
    Liu, Lei
    Tsuritani, Takehiro
    Morita, Itsuro
    Lopez, Victor
    Gonzalez de Dios, Oscar
    Pedro Fernandez-Palacios, Juan
    JOURNAL OF OPTICAL COMMUNICATIONS AND NETWORKING, 2015, 7 (01) : A106 - A117
  • [38] Data Center Optical Networks (DCON) with OpenFlow based Software Defined Networking (SDN)
    Zhao, Yongli
    Zhang, Jie
    Yang, Hui
    Yu, Xiaosong
    2013 8TH INTERNATIONAL ICST CONFERENCE ON COMMUNICATIONS AND NETWORKING IN CHINA (CHINACOM), 2013, : 771 - 775
  • [39] HybridFlow: A Lightweight Control Plane for Hybrid SDN in Enterprise Networks
    Huang, Siyuan
    Zhao, Jin
    Wang, Xin
    2016 IEEE/ACM 24TH INTERNATIONAL SYMPOSIUM ON QUALITY OF SERVICE (IWQOS), 2016,
  • [40] Enhanced local detouring mechanisms for rapid and lightweight failure recovery in OpenFlow networks
    Thorat, Pankaj
    Jeon, Seil
    Choo, Hyunseung
    COMPUTER COMMUNICATIONS, 2017, 108 : 78 - 93