Comparative Analysis Of Intrusion Detection Systems in SDN
Rehan Shams, Daniyal Omer Suri, Fozia Hanif, Pablo Otero · 2023
Networking industry has changed a lot in the past few years and as SDN being the new emerging technology of the future, security concerns have risen enormously. Control plane is separated from data plane in SDN providing the network administrators with more control by pushing application codes into the network also making it more vulnerable to attacks. DoS/DDoS are the most dominant attacks that a network of an organisation faces these days, because of the unsupervised network subscriptions and easily available attack tools/applications.This research aims to integrate the traditional open source IDS with Software Defined Networks and test their capabilities against malicious traffic injected by an attacker. In this paper, we compared two open source IDS Snort and Suricata with SDN and then deliberately injected malicious traffic. We time stamped the DoS/DDoS attack in both scenarios to compare Snort and Suricata true positive and false negative rates. From the results obtained we concluded that used IDS were successfully integrated with a prototype emulated network on Mininet and OpenDaylight being the remote controller and after injecting attacks into the network, it was seen that performance of Snort exceeded than that of Suricata. We propose Snort being the better IDS suited for industry standard deployment.