首页> 外文会议>International Conference on Innovations in Bio-Inspired Computing and Applications >Scalable and Dynamic Network Intrusion Detection and Prevention System
【24h】

Scalable and Dynamic Network Intrusion Detection and Prevention System

机译:可扩展和动态网络入侵检测和预防系统

获取原文

摘要

Network Intrusion Detection and Prevention Systems (NIDPS) are widely used to detect and thwart malicious activities and attacks. However, the existing NIDPS are monolithic/centralized, and hence they are very limited in terms of scalability and responsiveness. In this work, we address how to mitigate SYN Flooding attacks that can occur in the management network (OpenFlow) as well as in the production network taking into account the network scalability. Our suggested framework is a distributed and dynamic NIDPS that uses the Programming Protocol independent Packet Processors (P4) to process the network packets at the switch level and perform two main functions. First, it detects the SYN flooding attacks based on the SYN packets' rate and threshold. Secondly, our system uses a reviewed way to activate the SYN cookies in order to block/drop illegitimate packets. Our framework takes advantage of the switch programmability (i.e., using P4 language), distributed packet processing, and centralized Software Defined Networking (SDN) control, to provide an efficient and extensible NIDPS.
机译:网络入侵检测和预防系统(NIDPS)被广泛用于检测和挫败恶意活动和攻击。然而,现有的NIDPS是单一的/集中的,因此它们在可扩展性和响应性方面非常有限。在这项工作中,我们解决了如何减轻管理网络(OpenFlow)中可能发生的SYN泛洪攻击,并考虑到网络可扩展性。我们建议的框架是一种分布式和动态的NIDP,使用编程协议独立的数据包处理器(P4)来处理交换机级别并执行两个主要功能。首先,它根据SYN数据包的速率和阈值来检测SYN泛洪攻击。其次,我们的系统使用审核方式来激活SYN Cookie以阻止/删除非法数据包。我们的框架利用了开关可编程性(即,使用P4语言),分布式数据包处理和集中式软件定义网络(SDN)控制,以提供高效且可扩展的NIDPS。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号