SDN Security through System Call Learning
Danai Chasaki, Christopher Mansour · 2021
Software Defined Networking (SDN) has changed the way of designing and managing networks. This technology emerged from the efforts to make the networks more programmable. Programmability allows the development of various third-party applications that can be used by network administrators to implement essential networking functionalities. However, programmability also introduces security threats. In this paper we address the issue of malicious hosts running malicious applications that bypass the standard SDN based detection mechanisms. The SDN security system we are proposing periodically monitors the system calls utilization of the different SDN applications installed, learns from past system behavior using machine learning classifiers, and thus accurately detects the existence of an unusual activity or a malicious application.