Intrusion Prevention with Attack Traceback and Software-defined Control Plane for Campus Networks
Computer Science and Information Systems, Tome 18 (2021) no. 3.

Voir la notice de l'article provenant de la source Computer Science and Information Systems website

As traditional networks, the software-defined campus network also suffers from intrusion attacks. Current solutions for intrusion prevention cannot meet the requirements of the campus network. Existing methods of attack traceback are either limited to specific protocols or incur high overhead. To protect the data center (DC) of the campus network from internal and external attacks, we propose an Intrusion Prevention System (IPS) based on the coordinated control between the detection engine, the attack traceback agent, and the software-defined control plane. Our solution includes a novel algorithm to infer the best switch port for defending different attacks of varied scales based on the inverse HSA (Header Space Analysis) and the global view of the software-defined controller. The proposed scheme can effectively and timely block the malicious traffic not only protecting victim hosts from attacks but also preventing the whole network from suffering unwanted transmission burden. The proposed IPS is deployed on the bypass of the DC switch and collects network traffic by port mirroring. Compared with the traditional serial deployment, the new design helps defend the DC internal attacks, reduce the probability of network congestion, and avoid the single point of failure. The experimental results show that the overhead of our IPS is very low, which enables it to meet the real-time requirements. The average defense time is between 10 and 14 ms for the data center internal attacks of different scales. For external attacks, the maximum defense time is about 76 ms for a large-scale network with 100 switches.
Keywords: IPS, Intrusion Prevention System, SDN, Software-defined Network, Attack Traceback, Inverse Forwarding Function, HSA, Header Space Analysis, Campus Networks, DC, Data Center
@article{CSIS_2021_18_3_a12,
     author = {Guangfeng Guo and Junxing Zhang and Zhanfei Ma},
     title = {Intrusion {Prevention} with {Attack} {Traceback} and {Software-defined} {Control} {Plane} for {Campus} {Networks}},
     journal = {Computer Science and Information Systems},
     publisher = {mathdoc},
     volume = {18},
     number = {3},
     year = {2021},
     url = {http://geodesic.mathdoc.fr/item/CSIS_2021_18_3_a12/}
}
TY  - JOUR
AU  - Guangfeng Guo
AU  - Junxing Zhang
AU  - Zhanfei Ma
TI  - Intrusion Prevention with Attack Traceback and Software-defined Control Plane for Campus Networks
JO  - Computer Science and Information Systems
PY  - 2021
VL  - 18
IS  - 3
PB  - mathdoc
UR  - http://geodesic.mathdoc.fr/item/CSIS_2021_18_3_a12/
ID  - CSIS_2021_18_3_a12
ER  - 
%0 Journal Article
%A Guangfeng Guo
%A Junxing Zhang
%A Zhanfei Ma
%T Intrusion Prevention with Attack Traceback and Software-defined Control Plane for Campus Networks
%J Computer Science and Information Systems
%D 2021
%V 18
%N 3
%I mathdoc
%U http://geodesic.mathdoc.fr/item/CSIS_2021_18_3_a12/
%F CSIS_2021_18_3_a12
Guangfeng Guo; Junxing Zhang; Zhanfei Ma. Intrusion Prevention with Attack Traceback and Software-defined Control Plane for Campus Networks. Computer Science and Information Systems, Tome 18 (2021) no. 3. http://geodesic.mathdoc.fr/item/CSIS_2021_18_3_a12/