For Full-Text PDF, please login, if you are a member of IEICE,|
or go to Pay Per View on menu list, if you are a nonmember of IEICE.
A Collaborative Intrusion Detection System against DDoS for SDN
Xiaofan CHEN Shunzheng YU
IEICE TRANSACTIONS on Information and Systems
Publication Date: 2016/09/01
Online ISSN: 1745-1361
Type of Manuscript: LETTER
Category: Information Network
collaborative intrusion detection system (CIDS), distributed denial-of-service (DDoS), software defined networks (SDN), artificial neural network (ANN),
Full Text: PDF>>
DDoS remains a major threat to Software Defined Networks. To keep SDN secure, effective detection techniques for DDoS are indispensable. Most of the newly proposed schemes for detecting such attacks on SDN make the SDN controller act as the IDS or the central server of a collaborative IDS. The controller consequently becomes a target of the attacks and a heavy loaded point of collecting traffic. A collaborative intrusion detection system is proposed in this paper without the need for the controller to play a central role. It is deployed as a modified artificial neural network distributed over the entire substrate of SDN. It disperses its computation power over the network that requires every participating switch to perform like a neuron. The system is robust without individual targets and has a global view on a large-scale distributed attack without aggregating traffic over the network. Emulation results demonstrate its effectiveness.