DocumentCode :
2161908
Title :
Providing elasticity to intrusion detection systems in virtualized Software Defined Networks
Author :
Lopez, Martin Andreoni ; Duarte, Otto Carlos M.B.
Author_Institution :
Universidade Federal do Rio de Janeiro - UFRJ, GTA/COPPE, Brazil
fYear :
2015
fDate :
8-12 June 2015
Firstpage :
7120
Lastpage :
7125
Abstract :
This paper presents BroFlow, an Intrusion Detection and Prevention System based on Bro traffic analyzer, and on the global network-view feature of OpenFlow Application Programming Interface. BroFlow main contributions are: i) dynamic and elastic resource provision of machines under demand; ii) real-time detection of DoS attacks through simple algorithms implemented in a policy language for network events; iii) immediate reaction to DoS attacks and malicious packets, dropping flows close from their source; iv) strategic sensor positioning for attack detection in the network infrastructure shared by multi-tenants. A system prototype was developed and evaluated in the virtual environment Future Testbed Internet with Security (FITS). An evaluation of the system under attack shows that BroFlow guarantees the forwarding of legitimate packets at the maximal link rate, up to 90% reduction of the maximal network delay caused by the attack, and 50% of bandwidth gain compared with conventional firewalls approaches, even when the attackers are legitimate tenants acting in collusion.
Keywords :
Computer crime; Delays; Proposals; Switches; Virtual machining;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Communications (ICC), 2015 IEEE International Conference on
Conference_Location :
London, United Kingdom
Type :
conf
DOI :
10.1109/ICC.2015.7249462
Filename :
7249462
Link To Document :
بازگشت