• DocumentCode
    2161908
  • Title

    Providing elasticity to intrusion detection systems in virtualized Software Defined Networks

  • Author

    Lopez, Martin Andreoni ; Duarte, Otto Carlos M.B.

  • Author_Institution
    Universidade Federal do Rio de Janeiro - UFRJ, GTA/COPPE, Brazil
  • fYear
    2015
  • fDate
    8-12 June 2015
  • Firstpage
    7120
  • Lastpage
    7125
  • Abstract
    This paper presents BroFlow, an Intrusion Detection and Prevention System based on Bro traffic analyzer, and on the global network-view feature of OpenFlow Application Programming Interface. BroFlow main contributions are: i) dynamic and elastic resource provision of machines under demand; ii) real-time detection of DoS attacks through simple algorithms implemented in a policy language for network events; iii) immediate reaction to DoS attacks and malicious packets, dropping flows close from their source; iv) strategic sensor positioning for attack detection in the network infrastructure shared by multi-tenants. A system prototype was developed and evaluated in the virtual environment Future Testbed Internet with Security (FITS). An evaluation of the system under attack shows that BroFlow guarantees the forwarding of legitimate packets at the maximal link rate, up to 90% reduction of the maximal network delay caused by the attack, and 50% of bandwidth gain compared with conventional firewalls approaches, even when the attackers are legitimate tenants acting in collusion.
  • Keywords
    Computer crime; Delays; Proposals; Switches; Virtual machining;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Communications (ICC), 2015 IEEE International Conference on
  • Conference_Location
    London, United Kingdom
  • Type

    conf

  • DOI
    10.1109/ICC.2015.7249462
  • Filename
    7249462