A Hierarchical Fog Computing Framework for Network Attack Detection in SDN

Zakaria Abou El Houda, Lyes Khoukhi · 2022

In recent years, there has been a huge demand to secure Internet of Things (IoT) applications against the new emerging threats and attacks; these attacks are becoming increasingly sophisticated and have caused tremendous damage to academic and business organizations. Intrusion detection systems (IDS) have an essential role in ensuring network security. As new types of security threats emerge, conventional IDSs that rely on pattern matching are constrained by their need for new attack patterns. To address this problem, machine learning and deep learning (ML/DL) techniques have been proposed in the literature to improve the detection capability of traditional IDS. In this paper, we study a new problem of using a lightweight adaptive boosting technique (the AdaBoost algorithm) for intrusion detection in software defined networks (SDNs). In particular, we propose a hierarchical Fog Computing Framework, called ML-FoG, that uses both advanced ML techniques with a new feature selection scheme to efficiently detect security threats in SDNs; ML-FoG consists of: (1) a Network data Flow Collection module (NFC) that gathers network features in a scalable way; (2) a Gradient Boosting Feature Selection Module (GBSM) that selects the most informative and relevant features; and (3) a novel lightweight adaptive boosting scheme that uses AdaBoost to detect network security threats in a timely and effective manner. Experimental results using UNSW-NB15 demonstrate that ML-FoG outperforms state-of-the-art contributions in accuracy and detection rate, while greatly decreasing the computational complexity.

Read the paper · More papers on PaperTik