An Efficient Intrusion Detection Framework in Software-Defined Networking for Cybersecurity Applications

被引:10
|
作者
Alshammri, Ghalib H. [1 ,2 ]
Samha, Amani K. [3 ]
Hemdan, Ezz El-Din [4 ]
Amoon, Mohammed [1 ,4 ]
El-Shafai, Walid [5 ,6 ]
机构
[1] King Saud Univ, Community Coll, Dept Comp Sci, Riyadh 28095, Saudi Arabia
[2] Saudi Elect Univ, Sci Res, Riyadh, Saudi Arabia
[3] King Saud Univ, Coll Business Adm, Management Informat Syst Dept, Riyadh 28095, Saudi Arabia
[4] Menoufia Univ, Fac Elect Engn, Dept Comp Sci & Engn, Menoufia 32952, Egypt
[5] Prince Sultan Univ, Comp Sci Dept, Secur Engn Lab, Riyadh 11586, Saudi Arabia
[6] Menoufia Univ, Fac Elect Engn, Elect & Elect Commun Engn Dept, Menoufia 32952, Egypt
来源
CMC-COMPUTERS MATERIALS & CONTINUA | 2022年 / 72卷 / 02期
关键词
Deep neural network; DL; WEKA; network traffic; intrusion and anomaly detection; SDN; clustering and classification; KDD dataset; CONTROL PLANE; SECURITY; QOS; SDN;
D O I
10.32604/cmc.2022.025262
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Network management and multimedia data mining techniques have a great interest in analyzing and improving the network traffic process. In recent times, the most complex task in Software Defined Network (SDN) is security, which is based on a centralized, programmable controller. Therefore, monitoring network traffic is significant for identifying and revealing intrusion abnormalities in the SDN environment. Consequently, this paper provides an extensive analysis and investigation of the NSL-KDD dataset using five different clustering algorithms: K-means, Farthest First, Canopy, Density-based algorithm, and Exception-maximization (EM), using the Waikato Environment for Knowledge Analysis (WEKA) software to compare extensively between these five algorithms. Furthermore, this paper presents an SDN-based intrusion detection system using a deep learning (DL) model with the KDD (Knowledge Discovery in Databases) dataset. First, the utilized dataset is clustered into normal and four major attack categories via the clustering process. Then, a deep learning method is projected for building an efficient SDN-based intrusion detection system. The results provide a comprehensive analysis and a flawless reasonable study of different kinds of attacks incorporated in the KDD dataset. Similarly, the outcomes reveal that the proposed deep learning method provides efficient intrusion detection performance compared to existing techniques. For example, the proposed method achieves a detection accuracy of 94.21% for the examined dataset.
引用
收藏
页码:3529 / 3548
页数:20
相关论文
共 50 条
  • [41] Software-Defined Networking approaches for intrusion response in Industrial Control Systems: A survey
    Etxezarreta, Xabier
    Garitano, Inaki
    Iturbe, Mikel
    Zurutuza, Urko
    INTERNATIONAL JOURNAL OF CRITICAL INFRASTRUCTURE PROTECTION, 2023, 42
  • [42] Software-defined underwater acoustic networking platform and its applications
    Torres, Dustin
    Friedman, Jonathan
    Schmid, Thomas
    Srivastava, Mani B.
    Noh, Youngtae
    Gerla, Mario
    AD HOC NETWORKS, 2015, 34 : 252 - 264
  • [43] Enabling Practical Software-defined Networking Security Applications with OFX
    Sonchack, John
    Aviv, Adam J.
    Keller, Eric
    Smith, Jonathan M.
    23RD ANNUAL NETWORK AND DISTRIBUTED SYSTEM SECURITY SYMPOSIUM (NDSS 2016), 2016,
  • [44] A Dynamic Cybersecurity Protection Method based on Software-defined Networking for Industrial Control Systems
    Wang, Fang
    Qi, Weimin
    Qian, Tonghui
    2019 CHINESE AUTOMATION CONGRESS (CAC2019), 2019, : 1831 - 1834
  • [45] An Extension Approach for Threat Detection and Defense of Software-Defined Networking
    Xu, Hui
    Wang, Chunzhi
    Chen, Hongwei
    INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2016, 10 (02): : 365 - 374
  • [46] Cat deep system for intrusion detection in software defined networking
    Hande Y.
    Muddana A.
    International Journal of Intelligent Information and Database Systems, 2022, 15 (02) : 125 - 165
  • [47] Programmable Networks-From Software-Defined Radio to Software-Defined Networking
    Macedo, Daniel F.
    Guedes, Dorgival
    Vieira, Luiz F. M.
    Vieira, Marcos A. M.
    Nogueira, Michele
    IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2015, 17 (02): : 1102 - 1125
  • [48] Risk based intrusion detection system in software defined networking
    Chetouane, Ameni
    Karoui, Kamel
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2024, 36 (09):
  • [49] Joint DDoS detection system based on software-defined networking
    Song Y.
    Yang H.
    Wu W.
    Hu A.
    Gao S.
    Qinghua Daxue Xuebao/Journal of Tsinghua University, 2019, 59 (01): : 28 - 35
  • [50] Malware Detection for Mobile Devices Using Software-Defined Networking
    Jin, Ruofan
    Wang, Bing
    2013 SECOND GENI RESEARCH AND EDUCATIONAL EXPERIMENT WORKSHOP (GREE), 2013, : 81 - 88