An Effective Lightweight Intrusion Detection System with Blockchain to Mitigate Attacks in SDN/NFV Enabled Cloud

Ihsan H. Abdulqadder, Shijie Zhou, Israa T. Aziz, Deqing Zou, Xianjun Deng, Syed Muhammad Abrar Akber · 2021

Software defined network (SDN) and network function virtualization (NFV) are the two key technologies that support a large scale 5G environment composed of bunches of users. In this paper, the intrusion detection system (IDS) is provisioned in each layer to completely drop the malicious packets that have escaped in prior layers. The four-layer architecture presented in this work is the perception layer, data plane layer, control plane layer, and application layer. Each layer mitigates particular attacks that peculiarly participate in the network. Classification of attacker packets is handled by analyzing flow features and packet features. Initially, the 5G users are authenticated using the Prince algorithm with identity, password, MAC address, location, and physically unclonable function. Then optimal switches are selected to overwhelm flow table overloading attack by sea lion optimization algorithm. The flow rules in switches are secured through blockchain that maintains PHOTON based hashed flow rules. Flow features from the packets are extracted and classified using recurrent neural network (RNN) in the control plane and then the attack packets are dropped, normal packets are processed and suspicious packets are further classified in the application layer. NFV enabled cloud on the application layer classifies the suspicious packets into normal and malicious from the extracted packet feature based on multinomial naïve bayes (MNB) algorithm. The extensive simulation is performed in Network simulator and experimental results show the proposed attack mitigation is better in terms of detection rate, accuracy, precision, recall, and authentication time with respect to previous research.

Read the paper · More papers on PaperTik