SPSDN: A Security Platform for SDN Networks with an AI-based SQL Injection Attack Detection and Mitigation as An Example Service
Emir Yegnidemir, Rahamatullah Khondoker · 2024
As Software-Defined Networking (SDN) technology continues its rapid expansion, the landscape of security vulnerabilities is expected to undergo significant evolution in the near future [3] . SDN enables us not only to control the network from the centralized controller but it can also be utilized to detect and mitigate cyber-attacks. We proposed in this paper a security platform for SDN networks called SPSDN, which serves as a flexible platform capable of detecting various attack types. An example Artificial Intelligence (AI) CNN-based service for the detection and mitigation of SQL Injection attacks is presented as a demo in this paper. The choice of using a Convolutional Neural Network (CNN) in this scenario is supported by its better performance metrics compared to other models, as evidenced by the CNN’s accuracy of 96.43%, precision of 98.41%, and recall of 91.84%. In contrast, alternative methods such as Naive Bayes, SVM, KNN, and Decision Tree yielded varied results, with lower accuracy, precision, and recall scores, highlighting the CNN’s robustness in effectively classifying SQL injection queries [6] . The functionality of the proposed solution is demonstrated in a host communication scenario on Mininet. The system leverages a pre-trained Convolutional Neural Network (CNN) model, adapted to operate in a Python 2 environment on Ubuntu 20.04.6. The dataset and code for model training are available in [1] . The methodology employed in this project can be summarized as follows: Adaptation of the pre-trained CNN-based model to function within a Python 2 environment on Ubuntu 20.04.6. Development of a POX controller-based system integrating the CNN-based model to detect SQL injection attacks in SDN traffic and subsequently initiating port blocking for the attacker host to mitigate the attack. Future work will involve building additional attack detection methods on top of this security platform, eventually enabling network administrators to conveniently choose their preferred detection method via a user-friendly GUI tool, providing flexibility and customization to meet specific security requirements. In essence, our system not only provides a solution for the current challenge of SQL injection attacks in SDNs but also lays the groundwork for a more resilient and adaptive security infrastructure.