DocumentCode :
3735319
Title :
An event-based SDN architecture for network security analysis
Author :
Po-Ching Lin;Jyun-Chen Liu;Pin-Ren Chiou
Author_Institution :
Department of Computer Science and Information Engineering, Nation Chung Cheng University, Chiayi, Taiwan 62102Data Communication Business Group, Chung-Hwa Telecom, Taipei, Taiwan 10048
fYear :
2015
Firstpage :
159
Lastpage :
164
Abstract :
Software-defined networking (SDN), which decouples the control plane from traditionally proprietary network devices, is highly flexible and suitable for flow management. However, if the policy depends on the results of network security analysis, the controller will perform complicated packet processing such as packet reassembly and protocol analysis. Such processing will easily overburden the controller, and passing raw packets to the controller will result in large communications overheads. In this work, we propose an event-based SDN architecture for network security analysis. This architecture comes with an event extractor on the network device that performs protocol analysis to extract policy neutral events from network traffic. The network device looks up an extracted event in an event table to see whether a policy exists for the event. If not, it will ask the controller about the policy corresponding to this event and configure the policy in the event table accordingly. Since the controller deals with only high-level event descriptions, it is free from low-level packet processing. We evaluate this architecture by emulating it with the Bro intrusion detection system for event extraction from real traffic. The experimental results show the communication overheads between the network devices and the controller can be effectively reduced.
Keywords :
"Protocols","Computer architecture","Security","Communication networks","Process control","Performance evaluation","Feature extraction"
Publisher :
ieee
Conference_Titel :
Security Technology (ICCST), 2015 International Carnahan Conference on
Print_ISBN :
978-1-4799-8690-3
Electronic_ISBN :
2153-0742
Type :
conf
DOI :
10.1109/CCST.2015.7389675
Filename :
7389675
Link To Document :
بازگشت