Title
Implementation of SDN based network intrusion detection and prevention system
Abstract
In recent years, the rise of software-defined networks (SDN) have made network control more flexible, easier to set up and manage, and have provided a stronger ability to adapt to the changing demands of application development and network conditions. The network becomes easier to maintain, but also achieves improved security as a result of SDN. The architecture of SDN is designed for Control Plane and Forwarding Plane separation and uses open APIs to realize programmable control. SDN allows for the importing of third-party applications to improve network service, or even provide a new network service. In this paper, we present a defense mechanism, which can find attack packets previously identified through the Sniffer function, and once the abnormal flow is found, the protection mechanism of the Firewall function will be activated. For the capture of the packets, available libraries will be used to determine the properties and contents of the malicious packet, and to anticipate any possible attacks. Through the prediction of all latent malicious behaviors, our new defense algorithm can prevent potential losses like system failures or crashes and reduce the risk of being attacked.
Year
DOI
Venue
2015
10.1109/CCST.2015.7389672
2015 International Carnahan Conference on Security Technology (ICCST)
Keywords
Field
DocType
Firewall,Packet Sniffer,Software Defined Networks,SDN,OpenFlow,Controller,Defense Mechanism
Network service,Protection mechanism,Forwarding plane,Network intrusion detection,Firewall (construction),Computer science,Computer security,Network packet,Computer network,Stateful firewall,Control system,Distributed computing
Conference
ISSN
ISBN
Citations 
1071-6572
978-1-4799-8690-3
0
PageRank 
References 
Authors
0.34
15
2
Name
Order
Citations
PageRank
Pin-Jui Chen100.34
Yen-Wen Chen214424.44