Statistical Fingerprint-Based Ids In Sdn Architecture
Francesco Bigotto, Luca Boero, Mario Marchese, Sandro Zappatore · 2018
The number of people accessing the Internet is growing rapidly leading, on one hand, to new possible attacks used by cyber criminals and, on the other hand, to an increased complexity in the network management. It is crucial designing systems able to prevent cyber attacks. At the same time, many efforts are provided in order to get tools that can make easier network management. The Software Defined Networking (SDN) paradigm has been designed with this aim allowing network administrators to manage networks easily. This paper deals with an original Intrusion Detection System that exploits an SDN architecture to get the information needed to feed a statistical-fingerprint based IDS. Specifically the proposed system collects traffic data suitable to detect the possible presence of malware inside the network, and describes the design and implementation of an application developed upon a SDN controller (Ryu) and its role in the malware detection process.