Signature-based Intrusion Prevention System for Software Defined Networks using SNORT

Yeshan Kaushik, Abinaya Athmaraman, Ann Marry John, Shruti Raj · 2024

Using software-based controllers or application programming interfaces (APIs) to communicate with the network’s underlying hardware architecture and control traffic is known as software-defined networking (SDN). Through software, SDN can build and manage virtual networks or manage conventional hardware. The general idea is that the integration of SDN capabilities will directly result in vastly improved security. However, without the correct processing and implementation, SDN has the chance to potentially make networks more vulnerable to attacks and difficult to protect. There are three kinds of attacks that can be used to infiltrate a weak data plane: a device attack, protocol attack, and side channel attack. A device attack includes all those instances where an adversary targets software or hardware vulnerabilities in an SDN-capable switch to undermine the SDN’s data plane. A critical security concern revolves around the potential for a compromised SDN controller, particularly concerning attacks at the control plane layer. Intrusion Prevention Systems (IPS) have been widely deployed to enhance cloud security. In this paper, we establish an SDN-based IPS solution using SNORT, an open source IPS that uses a series of rules that help define malicious network activity and uses those rules to find packets that match against them and generates alerts. These sets of rules are updated regularly as SNORT is open source. The IPS system is meant be complemented with an existing IDS solution for securing a SDN.

Read the paper · More papers on PaperTik