DocumentCode
2161908
Title
Providing elasticity to intrusion detection systems in virtualized Software Defined Networks
Author
Lopez, Martin Andreoni ; Duarte, Otto Carlos M.B.
Author_Institution
Universidade Federal do Rio de Janeiro - UFRJ, GTA/COPPE, Brazil
fYear
2015
fDate
8-12 June 2015
Firstpage
7120
Lastpage
7125
Abstract
This paper presents BroFlow, an Intrusion Detection and Prevention System based on Bro traffic analyzer, and on the global network-view feature of OpenFlow Application Programming Interface. BroFlow main contributions are: i) dynamic and elastic resource provision of machines under demand; ii) real-time detection of DoS attacks through simple algorithms implemented in a policy language for network events; iii) immediate reaction to DoS attacks and malicious packets, dropping flows close from their source; iv) strategic sensor positioning for attack detection in the network infrastructure shared by multi-tenants. A system prototype was developed and evaluated in the virtual environment Future Testbed Internet with Security (FITS). An evaluation of the system under attack shows that BroFlow guarantees the forwarding of legitimate packets at the maximal link rate, up to 90% reduction of the maximal network delay caused by the attack, and 50% of bandwidth gain compared with conventional firewalls approaches, even when the attackers are legitimate tenants acting in collusion.
Keywords
Computer crime; Delays; Proposals; Switches; Virtual machining;
fLanguage
English
Publisher
ieee
Conference_Titel
Communications (ICC), 2015 IEEE International Conference on
Conference_Location
London, United Kingdom
Type
conf
DOI
10.1109/ICC.2015.7249462
Filename
7249462
Link To Document