Centralized and Distributed Intrusion Detection for Resource Constrained Wireless SDN Networks

03/01/2021
by   Gustavo A. Nunez Segura, et al.
0

Software-defined networking (SDN) was devised to simplify network management and automate infrastructure sharing in wired networks. These benefits motivated the application of SDN in wireless sensor networks to leverage solutions for complex applications. However, some of the core SDN traits turn the networks prone to denial of service attacks (DoS). There are proposals in the literature to detect DoS in wireless SDN networks, however, not without shortcomings: there is little focus on resource constraints, high detection rates have been reported only for small networks, and the detection is disengaged from the identification of the type of the attack or the attacker. Our work targets these shortcomings by introducing a lightweight, online change point detector to monitor performance metrics that are impacted when the network is under attack. A key novelty is that the proposed detector is able to operate in either centralized or distributed mode. The centralized detector has very high detection rates and can further distinguish the type of the attack (from a list of known attacks). On the other hand, the distributed detector provides information that allows to identify the nodes launching the attack. Our proposal is tested over IEEE 802.15.4 networks. The results show detection rates exceeding 96% in networks of 36 and 100 nodes and identification of the type of the attack with a probability exceeding 0.89 when using the centralized approach. Additionally, for some types of attack it was possible to pinpoint the attackers with an identification probability over 0.93 when using distributed detectors.

READ FULL TEXT

page 1

page 10

page 12

page 13

page 14

page 15

page 17

page 18

research
03/26/2020

Denial of Service Attacks Detection in Software-Defined Wireless Sensor Networks

Software-defined networking (SDN) is a promising technology to overcome ...
research
06/24/2020

DDoSNet: A Deep-Learning Model for Detecting Network Attacks

Software-Defined Networking (SDN) is an emerging paradigm, which evolved...
research
08/03/2022

A Novel Approach To Network Intrusion Detection System Using Deep Learning For Sdn: Futuristic Approach

Software-Defined Networking (SDN) is the next generation to change the a...
research
12/27/2019

Detecting DDoS Attack on SDN Due to Vulnerabilities in OpenFlow

Software Defined Networking (SDN) is a network paradigm shift that facil...
research
03/15/2019

AccFlow: Defending Against the Low-Rate TCP DoS Attack in Wireless Sensor Networks

Because of the open nature of the Wireless Sensor Networks (WSN), the De...
research
07/27/2019

Q-MIND: Defeating Stealthy DoS Attacks in SDN with a Machine-learning based Defense Framework

Software Defined Networking (SDN) enables flexible and scalable network ...
research
09/22/2020

ORACLE: Collaboration of Data and Control Planes to Detect DDoS Attacks

The possibility of programming the control and data planes, enabled by t...

Please sign up or login with your details

Forgot password? Click here to reset