Visible to the public The APT detection method in SDN

TitleThe APT detection method in SDN
Publication TypeConference Paper
Year of Publication2017
AuthorsShan-Shan, J., Ya-Bin, X.
Conference Name2017 3rd IEEE International Conference on Computer and Communications (ICCC)
KeywordsAPT, APT detection method, communication protocol, Computer crime, computer network security, data plane, Discrete Fourier transforms, Hidden Markov models, HMM, network framework, OpenFlow, process control, pubcrawl, Resiliency, Scalability, SDN, SDN controller plane, SDN security, software defined networking, software programming, Switches
Abstract

SDN is a new network framework which can be controlled and defined by software programming, and OpenFlow is the communication protocol between SDN controller plane and data plane. With centralized control of SDN, the network is more vulnerable encounter APT than traditional network. After deeply analyzing the process of APT at each stage in SDN, this paper proposes the APT detection method based on HMM, which can fully reflect the relationship between attack behavior and APT stage. Experiment shows that the method is more accurate to detect APT in SDN, and less overhead.

URLhttps://ieeexplore.ieee.org/document/8322741
DOI10.1109/CompComm.2017.8322741
Citation Keyshan-shan_apt_2017