Flow-based Intrusion Detection System for SDN

Georgi Ajaeiya, Nareg Adalian, Imad H. Elhajj, Ayman Kayssi, Ali Chehab · 2017

Software-defined networks (SDN) are vulnerable to most of the attacks that traditional networks are vulnerable to. In addition, SDN has introduced new vulnerabilities through its unique architecture such as those related to the southbound and northbound controller interfaces. In this paper, we introduce a lightweight flow-based Intrusion Detection System (IDS) that periodically gathers statistical information about flows from SDN OpenFlow switches, and analyzes traffic information by extracting and aggregating a set of features. The proposed IDS system proved to be accurate with a high detection rate at 0.98 measured by the F1 score of the classification model and a relatively low false alarm rate.

Read the paper · More papers on PaperTik