Publicaciones

Improving early attack detection in networks with sFlow and SDN

Fecha de publicación: 13 de septiembre de 2018

Autores: Leal, Alexander Botero, Alexander Jacob, Eduardo
Tipo:Artículo de revista científica
Detalles de la publicación
Serie: - Título del libro: -
Capítulo: - Edición: -
Volumen: - Revista: Applied Computer Sciences in Engineering. WEA 2018. Communications in Computer and Information Science
Número: - Páginas: -
ISBN/ISSN: - Lugar de la publicación: -
Referencia: https://doi.org/10.1007/978-3-030-00353-1_29
Descargar BibTex
Abstract

Network monitoring is a paramount aspect for the detection of abnormal and malicious activity. However, this feature must go hand by hand with mitigation techniques. On SDN environments, control techniques may be easily developed as a result of its ability for programming the network. In this work, we take advantage of this fact to improve the network security using the sFlow monitoring tool along with the SDN controller. We present an architecture where sFlow is in charge of detecting network anomalies defined by user rules, while the SDN technology is responsible to mitigate the intrusion. Our testbed has been implemented on Mininet and the SDN environment is governed by Opendaylight controller and the OpenFlow southbound protocol. Experimental validation demonstrate that our system can effectively report various types of intrusion associated with the reconnaissance phase of an attack.