Reduction of the Delays Within an Intrusion Detection System (IDS) Based on Software Defined Networking (SDN)

Software Defined Networking (SDN) is a very useful tool not only to manage networks but also to increase network security, in particular by implementing Intrusion Detection Systems (IDS) directly into the SDN architecture. The implementation of IDS within the SDN paradigm can simplify the implementa...

Full description

Bibliographic Details
Main Authors: Alessandro Fausto, Giovanni Gaggero, Fabio Patrone, Mario Marchese
Format: Article
Language:English
Published: IEEE 2022-01-01
Series:IEEE Access
Subjects:
Online Access:https://ieeexplore.ieee.org/document/9919834/
_version_ 1797990912352059392
author Alessandro Fausto
Giovanni Gaggero
Fabio Patrone
Mario Marchese
author_facet Alessandro Fausto
Giovanni Gaggero
Fabio Patrone
Mario Marchese
author_sort Alessandro Fausto
collection DOAJ
description Software Defined Networking (SDN) is a very useful tool not only to manage networks but also to increase network security, in particular by implementing Intrusion Detection Systems (IDS) directly into the SDN architecture. The implementation of IDS within the SDN paradigm can simplify the implementation, speed up incident responses, and, in general, allow to promptly react to cyber attacks through proper countermeasures. Nevertheless, embedding IDS within SDN also introduces delays that cannot be tolerated in specific network environments, like industrial control systems. This paper focuses on the implementation of an IDS based on Machine Learning (ML) algorithms into an SDN architecture and proposes a very practical approach to reduce the delay by using the sequential implementation of prototypes of increasing software and hardware complexity so allowing quick tests to highlight the main problems, solve them and pass to the next operative step. A fully validated performance evaluation is then shown by exploiting all the presented solutions and by using further improved hardware features. The overall performance is very good and compliant with most, even if not yet all, industrial control systems constraints. Results show how the proposed solutions provide a significant improvement of the latency so opening the door to a real implementation in the field.
first_indexed 2024-04-11T08:43:08Z
format Article
id doaj.art-6702ab84a891418a8a9c6dad1d47a65a
institution Directory Open Access Journal
issn 2169-3536
language English
last_indexed 2024-04-11T08:43:08Z
publishDate 2022-01-01
publisher IEEE
record_format Article
series IEEE Access
spelling doaj.art-6702ab84a891418a8a9c6dad1d47a65a2022-12-22T04:34:02ZengIEEEIEEE Access2169-35362022-01-011010985010986210.1109/ACCESS.2022.32149749919834Reduction of the Delays Within an Intrusion Detection System (IDS) Based on Software Defined Networking (SDN)Alessandro Fausto0Giovanni Gaggero1https://orcid.org/0000-0001-6404-2451Fabio Patrone2https://orcid.org/0000-0002-0983-9131Mario Marchese3https://orcid.org/0000-0002-9626-3483Department of Electrical, Electronics and Telecommunications Engineering and Naval Architecture—DITEN, University of Genoa, Genoa, ItalyDepartment of Electrical, Electronics and Telecommunications Engineering and Naval Architecture—DITEN, University of Genoa, Genoa, ItalyDepartment of Electrical, Electronics and Telecommunications Engineering and Naval Architecture—DITEN, University of Genoa, Genoa, ItalyDepartment of Electrical, Electronics and Telecommunications Engineering and Naval Architecture—DITEN, University of Genoa, Genoa, ItalySoftware Defined Networking (SDN) is a very useful tool not only to manage networks but also to increase network security, in particular by implementing Intrusion Detection Systems (IDS) directly into the SDN architecture. The implementation of IDS within the SDN paradigm can simplify the implementation, speed up incident responses, and, in general, allow to promptly react to cyber attacks through proper countermeasures. Nevertheless, embedding IDS within SDN also introduces delays that cannot be tolerated in specific network environments, like industrial control systems. This paper focuses on the implementation of an IDS based on Machine Learning (ML) algorithms into an SDN architecture and proposes a very practical approach to reduce the delay by using the sequential implementation of prototypes of increasing software and hardware complexity so allowing quick tests to highlight the main problems, solve them and pass to the next operative step. A fully validated performance evaluation is then shown by exploiting all the presented solutions and by using further improved hardware features. The overall performance is very good and compliant with most, even if not yet all, industrial control systems constraints. Results show how the proposed solutions provide a significant improvement of the latency so opening the door to a real implementation in the field.https://ieeexplore.ieee.org/document/9919834/Cybersecurityintrusion detection system (IDS)software defined networking (SDN)OpenFlowkey performance indicators (KPI)
spellingShingle Alessandro Fausto
Giovanni Gaggero
Fabio Patrone
Mario Marchese
Reduction of the Delays Within an Intrusion Detection System (IDS) Based on Software Defined Networking (SDN)
IEEE Access
Cybersecurity
intrusion detection system (IDS)
software defined networking (SDN)
OpenFlow
key performance indicators (KPI)
title Reduction of the Delays Within an Intrusion Detection System (IDS) Based on Software Defined Networking (SDN)
title_full Reduction of the Delays Within an Intrusion Detection System (IDS) Based on Software Defined Networking (SDN)
title_fullStr Reduction of the Delays Within an Intrusion Detection System (IDS) Based on Software Defined Networking (SDN)
title_full_unstemmed Reduction of the Delays Within an Intrusion Detection System (IDS) Based on Software Defined Networking (SDN)
title_short Reduction of the Delays Within an Intrusion Detection System (IDS) Based on Software Defined Networking (SDN)
title_sort reduction of the delays within an intrusion detection system ids based on software defined networking sdn
topic Cybersecurity
intrusion detection system (IDS)
software defined networking (SDN)
OpenFlow
key performance indicators (KPI)
url https://ieeexplore.ieee.org/document/9919834/
work_keys_str_mv AT alessandrofausto reductionofthedelayswithinanintrusiondetectionsystemidsbasedonsoftwaredefinednetworkingsdn
AT giovannigaggero reductionofthedelayswithinanintrusiondetectionsystemidsbasedonsoftwaredefinednetworkingsdn
AT fabiopatrone reductionofthedelayswithinanintrusiondetectionsystemidsbasedonsoftwaredefinednetworkingsdn
AT mariomarchese reductionofthedelayswithinanintrusiondetectionsystemidsbasedonsoftwaredefinednetworkingsdn