Submitted:
27 October 2023
Posted:
30 October 2023
You are already at the latest version
Abstract
Keywords:
1. Introduction
- We introduce a novel approach to deploying chains of IDSs in the data plane, enhancing intrusion detection rates and reducing dropped data packets. This strategic distribution of multiple IDS chains in the data plane not only avoids controller overload but also contributes to effective intrusion detection.
- We propose a creative centroid-based modification of the K-means clustering method, which efficiently groups incoming data flows to reduce data transmission delays.
- To address the complex joint optimization problem, we present a two-phase algorithm that effectively achieves our optimization goals.
- Our paper delves deep into the intricacies of flow grouping and the association of flow groups with IDS chains under varying scenarios. We introduce two distinct models for this association process: the minimum cost 2-D matching and the minimum cost 3-D matching.
- We provide a comprehensive evaluation of our approach on a real testbed under various measurements, demonstrating its practical effectiveness.
2. Related Work
3. Background and Motivation
4. IDSMatch: Deploying IDS Chains in SDN
- Perform clustering for the pair using a distance metric defined as the sum of distances from to the center and from to the center within a cluster with its central point at . The distance between each host and the cluster center is computed as the cumulative number of hops.
- Find balanced GroupFlows based on the amount of traffic for each group.
- Employ the standard perfect matching technique to establish pairs between cluster centers and IDS chain configurations. Note that the connections between IDS chain heads and tails are not fixed and can be reconfigured as needed.
| Algorithm 1 Balanced-Flow Grouping |
|
| Algorithm 2 Perfect Minimum Bipartite Matching |
|
5. Evaluation
5.1. Network Delay under Different Scale of Incoming Traffic
5.2. Number of Hops under Different Scales of Incoming Traffic
5.3. Network Delay under Varying Weights and Varying Number of Flows
5.4. Unbalancing Factor
6. Conclusions
Acknowledgments
Conflicts of Interest
References
- Cox, J.H.; Chung, J.; Donovan, S.; Ivey, J.; Clark, R.J.; Riley, G.; Owen, H.L. Advancing software-defined networks: A survey. IEEE Access 2017, 5, 25487–25526. [Google Scholar] [CrossRef]
- Hakiri, A.; Gokhale, A.; Berthou, P.; Schmidt, D.C.; Gayraud, T. Software-defined networking: Challenges and research opportunities for future internet. Computer Networks 2014, 75, 453–471. [Google Scholar] [CrossRef]
- Yoon, C.; Park, T.; Lee, S.; Kang, H.; Shin, S.; Zhang, Z. Enabling security functions with SDN: A feasibility study. Computer Networks 2015, 85, 19–35. [Google Scholar] [CrossRef]
- Niknami, N.; Wu, J. Enhancing Load Balancing by Intrusion Detection System Chain on SDN Data Plane. In Proceedings of the Proc. of the IEEE Conf. on Communications and Network Security (CNS), 2022. [Google Scholar]
- Shipulin, K. We need to talk about IDS signatures. Network Security 2018, 2018, 8–13. [Google Scholar] [CrossRef]
- Zwane, S.; Tarwireyi, P.; Adigun, M. Ensemble learning approach for flow-based intrusion detection system. In Proceedings of the 2019 IEEE AFRICON. IEEE, 2019; pp. 1–8. [Google Scholar]
- Alzahrani, A.O.; Alenazi, M.J. Designing a network intrusion detection system based on machine learning for software defined networks. Future Internet 2021, 13, 111. [Google Scholar] [CrossRef]
- Muthamil Sudar, K.; Deepalakshmi, P. An intelligent flow-based and signature-based IDS for SDNs using ensemble feature selection and a multi-layer machine learning-based classifier. Journal of Intelligent & Fuzzy Systems 2021, 40, 4237–4256. [Google Scholar]
- Niknami, N.; Inkrott, E.; Wu, J. Towards Analysis of the Performance of IDSs in Software-Defined Networks.
- Latah, M.; Toker, L. An efficient flow-based multi-level hybrid intrusion detection system for software-defined networks. CCF Transactions on Networking 2020, 3, 261–271. [Google Scholar] [CrossRef]
- Zhao, X.; Su, H.; Sun, Z. An Intrusion Detection System Based on Genetic Algorithm for Software-Defined Networks. Mathematics 2022, 10, 3941. [Google Scholar] [CrossRef]
- Cui, J.; Zhang, J.; He, J.; Zhong, H.; Lu, Y. DDoS detection and defense mechanism for SDN controllers with K-Means. In Proceedings of the 2020 IEEE/ACM 13th International Conference on Utility and Cloud Computing (UCC). IEEE, 2020; pp. 394–401. [Google Scholar]
- Niknami, N.; Wu, J. Entropy-KL-ML: Enhancing the Entropy-KL-based Anomaly Detection on Software-Defined Networks. IEEE Transactions on Network Science and Engineering 2022. [Google Scholar] [CrossRef]
- Yazdinejadna, A.; Parizi, R.M.; Dehghantanha, A.; Khan, M.S. A kangaroo-based intrusion detection system on software-defined networks. Computer Networks 2021, 184, 107688. [Google Scholar] [CrossRef]
- Goo, Y.H.; Lee, S.H.; Choi, S.; Choi, M.J.; Kim, M.S. A traffic grouping method using the correlation model of network flow. In Proceedings of the Proc. of IEEE 19th Asia-Pacific Network Operations and Management Symposium (APNOMS), 2017; pp. 386–390. [Google Scholar]
- Chakraborty, N. Intrusion detection system and intrusion prevention system: A comparative study. Intl. Journal of Computing and Business Research (IJCBR) 2013, 4, 1–8. [Google Scholar]
- Qaddoori, S.L.; Ali, Q.I. AN IN-DEPTH CHARACTERIZATION OF INTRUSION DETECTION SYSTEMS (IDS). Journal of Modern Technology and Engineering 2021, 6, 161–188. [Google Scholar]
- Khraisat, A.; Gondal, I.; Vamplew, P.; Kamruzzaman, J. Survey of intrusion detection systems: techniques, datasets and challenges. Cybersecurity 2019, 2, 1–22. [Google Scholar] [CrossRef]
- McKeown, N.; Anderson, T.; Balakrishnan, H.; Parulkar, G.; Peterson, L.; Rexford, J.; Shenker, S.; Turner, J. OpenFlow: enabling innovation in campus networks. ACM SIGCOMM Computer Communication Review 2008, 38, 69–74. [Google Scholar] [CrossRef]
- Hande, Y.; Muddana, A. A survey on intrusion detection system for software defined networks (SDN). In Research Anthology on Artificial Intelligence Applications in Security; 2021; pp. 467–489.
- Hande, Y.; Muddana, A.; Darade, S. Software-defined network-based intrusion detection system. In Innovations in Electronics and Communication Engineering; Springer, 2018; pp. 535–543.
- MacQueen, J.; et al. Some methods for classification and analysis of multivariate observations. In Proceedings of the Proc. of 5th Berkeley Symposium on Mathematical Statistics and Probability, 1967; Vol. 1, pp. 281–297.
- Malinen, M.I.; Fränti, P. Balanced k-means for clustering. In Proceedings of the Intl. Workshops on Statistical Techniques in Pattern Recognition and Structural and Syntactic Pattern Recognition. Springer, 2014; pp. 32–41. [Google Scholar]
- Chang, X.; Nie, F.; Ma, Z.; Yang, Y. Balanced k-means and min-cut clustering. arXiv 2014, arXiv:1411.6235. [Google Scholar]
- Burkard, R.; Dell’Amico, M.; Martello, S. Assignment problems: revised reprint; SIAM, 2012.
- Karp, R.M. An algorithm to solve the m× n assignment problem in expected time O (mn log n). Networks 1980, 10, 143–152. [Google Scholar] [CrossRef]
- Johnson, T.; Wu, J. Improvements to Worker Assignment in Bike Sharing Systems. In Proceedings of the Proc. of IEEE 18th Intl. Conf. on Mobile Ad Hoc and Smart Systems (MASS), 2021; pp. 639–644. [Google Scholar]
- Vattani, A. The hardness of k-means clustering in the plane. Manuscript 2009, 617. [Google Scholar]
- Mahajan, M.; Nimbhorkar, P.; Varadarajan, K. The planar k-means problem is NP-hard. In Proceedings of the Proc. of Intl. Workshop on Algorithms and Computation, 2009; pp. 274–285. [Google Scholar]
- Thorpe, M.; Theil, F.; Johansen, A.M.; Cade, N. Convergence of the k-means minimization problem using Γ-convergence. SIAM Journal on Applied Mathematics 2015, 75, 2444–2474. [Google Scholar] [CrossRef]
- Coates, A.; Ng, A.; Lee, H. An analysis of single-layer networks in unsupervised feature learning. In Proceedings of the Proc. of 14th Intl. Conf. on Artificial Intelligence and Statistics, 2011; pp. 215–223. [Google Scholar]
- Elkan, C. Using the triangle inequality to accelerate k-means. In Proceedings of the Proc. of 20th Intl Conf. on Machine Learning (ICML), 2003; pp. 147–153. [Google Scholar]
- Hamerly, G. Making k-means even faster. In Proceedings of the Proc. of Intl. Conf. on Data Mining (SIAM), 2010; pp. 130–140. [Google Scholar]
- Duan, Y.; Wu, J. Spatial-temporal inventory rebalancing for bike sharing systems with worker recruitment. IEEE Transactions on Mobile Computing 2020. [Google Scholar] [CrossRef]
- Biswas, R. Mitigation of Different Network Attacks and Optimization in Software Defined Network. PhD thesis, Temple University, 2021.













| Shortest Path | Balanced | Matching | ||||
|---|---|---|---|---|---|---|
| Flow | Group | IDS | Group | IDS | Group | IDS |
| Total | 34 | 38 | 34 | |||
| Flows | Shortest Path | Balancing | Matching |
|---|---|---|---|
| IDS Chain 1 | |||
| IDS Chain 2 | |||
| IDS Chain 3 |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2023 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (http://creativecommons.org/licenses/by/4.0/).