NOMS 2018 - 2018 IEEE/IFIP Network Operations and Management Symposium 2018
DOI: 10.1109/noms.2018.8406313
|View full text |Cite
|
Sign up to set email alerts
|

Lightweight IPS for port scan in OpenFlow SDN networks

Abstract: Security has been one of the major concerns for the computer network community due to resource abuse and malicious flows intrusion. Before a network or a system is attacked, a port scan is typically performed to discover vulnerabilities, like open ports, which may be used to access and control them. Several studies have addressed Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS) methods for detecting malicious activities, based on received flows or packet data analysis. However, those me… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1
1

Citation Types

0
10
0
1

Year Published

2020
2020
2023
2023

Publication Types

Select...
3
3
1

Relationship

1
6

Authors

Journals

citations
Cited by 13 publications
(12 citation statements)
references
References 9 publications
0
10
0
1
Order By: Relevance
“…Once an anomalous increase in the rate is detected, the controller requests the statistics of the switch. Then, we used the method proposed in the research 4 to detect the occurrence of a port scan. Since the port scan detection process is done only when it is triggered, the frequency of detection will be considerably reduced compared to methods that performs the detection every set interval.…”
Section: Proposed Port Scan Detection Methodsmentioning
confidence: 99%
See 1 more Smart Citation
“…Once an anomalous increase in the rate is detected, the controller requests the statistics of the switch. Then, we used the method proposed in the research 4 to detect the occurrence of a port scan. Since the port scan detection process is done only when it is triggered, the frequency of detection will be considerably reduced compared to methods that performs the detection every set interval.…”
Section: Proposed Port Scan Detection Methodsmentioning
confidence: 99%
“…OpenFlow can collect traffic statistics from OF‐compatible devices, so that the communication can be handled in a switch‐by‐switch basis. This feature has been shown effective for network security measures 4,8,9 . For instance, Neu et al 4 .…”
Section: Introductionmentioning
confidence: 99%
“…In [48] authors use the existing Snort IDS for attacker information, and show that denial-of-service attacks can be monitored and mitigated by combining SDN security mechanisms, while the authors in [49] use a hybrid model of two types of machine learning (SVM and SOM) to improve the accuracy of DDoS attack detection relative to a separate machine learning approach. Neu et al [50] present an SDN solution to prevent port scan attacks. They used the statistics collected on SDN networks and updated the OpenFlow routing rules when a port scan was observed.…”
Section: Intrusion Prevention Systemsmentioning
confidence: 99%
“…Os controladores SDN se comunicam com os dispositivos de encaminhamento (plano de dados) através de uma API Southbound (ex: Open-Flow) para definir regras de encaminhamento, além de extrair informac ¸ões (como estatísticas e eventos) que serão enviadas para as aplicac ¸ões [Kim and Feamster 2013]. Por exemplo, um controlador pode ser utilizado por diferentes aplicac ¸ões, como depuradores [Tavares et al 2017] e sistemas de prevenc ¸ão de intrusões [Neu et al 2018]. O plano de dados, por sua vez, é responsável por realizar o encaminhamento de pacotes entre os dispositivos, abstraindo o hardware utilizado [Farhad et al 2014].…”
Section: Sdn E Programabilidade Do Plano De Dadosunclassified