Abstract

In recent years, there have been an increasing number of attacks on networks, such as the distributed denial-of-service attack. However, the traditional network is not sufficiently flexible to control the huge amount of traffic that now passes through an intrusion detection system. With SDN, which separates control planes and data planes for programmability, elasticity, and simplicity, it becomes possible to force traffic to pass through an IDS by simply rerouting or mirroring traffic to an IDS. This article focuses on how to distribute traffic to multiple IDSs in order to increase the detection of network attacks and balance IDS loads. A clustering-based flow grouping scheme that distributes flows according to routing information and flow data rate is proposed. Through experiments with a virtualized testbed, we show that the proposed scheme detects network attacks more quickly and achieves a better balance of traffic loads on the IDSs.

Full Text
Paper version not known

Talk to us

Join us for a 30 min session where you can share your feedback and ask us any queries you have

Schedule a call

Disclaimer: All third-party content on this website/platform is and will remain the property of their respective owners and is provided on "as is" basis without any warranties, express or implied. Use of third-party content does not indicate any affiliation, sponsorship with or endorsement by them. Any references to third-party content is to identify the corresponding services and shall be considered fair use under The CopyrightLaw.