CIPA: A collaborative intrusion prevention architecture for programmable network and SDN. Issue 58 (May 2016)
- Record Type:
- Journal Article
- Title:
- CIPA: A collaborative intrusion prevention architecture for programmable network and SDN. Issue 58 (May 2016)
- Main Title:
- CIPA: A collaborative intrusion prevention architecture for programmable network and SDN
- Authors:
- Chen, Xiao-Fan
Yu, Shun-Zheng - Abstract:
- Highlights: We detect DDoS, worm spreading and scanning in different network sizes. CIPA performs well in both simulated networks and real-world SDN environment. The detection rate of CIPA increases as attack flow becomes more dispersed. The false positive rate of CIPA is lower than 4%. The communication and computation overhead of CIPA are proved to be low. Abstract: Coordinated intrusion, like DDoS, Worm outbreak and Botnet, is a major threat to network security nowadays and will continue to be a threat in the future. To ensure the Internet security, effective detection and mitigation for such attacks are indispensable. In this paper, we propose a novel collaborative intrusion prevention architecture, i.e. CIPA, aiming at confronting such coordinated intrusion behavior. CIPA is deployed as a virtual network of an artificial neural net over the substrate of networks. Taking advantage of the parallel and simple mathematical manipulation of neurons in a neural net, CIPA can disperse its lightweight computation power to the programmable switches of the substrate. Each programmable switch virtualizes one to several neurons. The whole neural net functions like an integrated IDS/IPS. This allows CIPA to detect distributed attacks on a global view. Meanwhile, it does not require high communication and computation overhead. It is scalable and robust. To validate CIPA, we have realized a prototype on Software-Defined Networks. We also conducted simulations and experiments. TheHighlights: We detect DDoS, worm spreading and scanning in different network sizes. CIPA performs well in both simulated networks and real-world SDN environment. The detection rate of CIPA increases as attack flow becomes more dispersed. The false positive rate of CIPA is lower than 4%. The communication and computation overhead of CIPA are proved to be low. Abstract: Coordinated intrusion, like DDoS, Worm outbreak and Botnet, is a major threat to network security nowadays and will continue to be a threat in the future. To ensure the Internet security, effective detection and mitigation for such attacks are indispensable. In this paper, we propose a novel collaborative intrusion prevention architecture, i.e. CIPA, aiming at confronting such coordinated intrusion behavior. CIPA is deployed as a virtual network of an artificial neural net over the substrate of networks. Taking advantage of the parallel and simple mathematical manipulation of neurons in a neural net, CIPA can disperse its lightweight computation power to the programmable switches of the substrate. Each programmable switch virtualizes one to several neurons. The whole neural net functions like an integrated IDS/IPS. This allows CIPA to detect distributed attacks on a global view. Meanwhile, it does not require high communication and computation overhead. It is scalable and robust. To validate CIPA, we have realized a prototype on Software-Defined Networks. We also conducted simulations and experiments. The results demonstrate that CIPA is effective. … (more)
- Is Part Of:
- Computers & security. Issue 58(2016)
- Journal:
- Computers & security
- Issue:
- Issue 58(2016)
- Issue Display:
- Volume 58, Issue 58 (2016)
- Year:
- 2016
- Volume:
- 58
- Issue:
- 58
- Issue Sort Value:
- 2016-0058-0058-0000
- Page Start:
- 1
- Page End:
- 19
- Publication Date:
- 2016-05
- Subjects:
- Collaborative intrusion prevention -- Collaborative intrusion detection system (CIDS) -- Large-scale distributed attacks -- Programmable network -- Software-defined networks (SDN)
Computer security -- Periodicals
Electronic data processing departments -- Security measures -- Periodicals
005.805 - Journal URLs:
- http://www.sciencedirect.com/science/journal/01674048 ↗
http://www.elsevier.com/journals ↗ - DOI:
- 10.1016/j.cose.2015.11.008 ↗
- Languages:
- English
- ISSNs:
- 0167-4048
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - 3394.781000
British Library DSC - BLDSS-3PM
British Library HMNTS - ELD Digital store - Ingest File:
- 1803.xml