Design of an SDN Security Mechanism to Detect Malicious Activities

Christopher Mansour, Danai Chasaki · 2018

Software Defined Networks (SDN) is a modern networking paradigm that introduces lots of benefits to the next-generation networks. It offers the necessary programmability that allows the dynamic configuration of the networks and thus the deployment of new services on the fly to meet the different use cases. This programmability allows the development of a plethora of third-party applications that can be used by network administrators in order to implement different networking functionalities. However, this programmability also induces various threats regarding potential malicious activities against the SDN networks. In this paper, we propose the design and implementation of an SDN security mechanism that helps in the detection of malicious activities that might target the SDN network. The design we are proposing leverages the benefits of centralized control and programmability of SDN in order to periodically monitor the system calls utilization of the different SDN applications installed and statistically correlates such information to the baseline/benchmark information, thus detecting the existence of an unusual activity or a malicious application.

Read the paper · More papers on PaperTik