Design and Implementation Adaptive Intrusion Prevention System (IPS) for Attack Prevention in Software-Defined Network (SDN) Architecture
Title | Design and Implementation Adaptive Intrusion Prevention System (IPS) for Attack Prevention in Software-Defined Network (SDN) Architecture |
Publication Type | Conference Paper |
Year of Publication | 2018 |
Authors | Pratama, R. F., Suwastika, N. A., Nugroho, M. A. |
Conference Name | 2018 6th International Conference on Information and Communication Technology (ICoICT) |
Date Published | May 2018 |
Publisher | IEEE |
ISBN Number | 978-1-5386-4572-7 |
Keywords | Adaptive Intrusion Prevention System, adaptive IPS, Adaptive systems, attack prevention, attacker host, Computer architecture, computer network security, Fuzzy logic, fuzzy set theory, host attacks, intrusion prevention system, IP networks, IPS, logic architecture, logic network, malicious packet, Metrics, pubcrawl, resilience, Resiliency, SDN network, security, Servers, Software, software defined networking, software-defined network |
Abstract | Intrusion Prevention System (IPS) is a tool for securing networks from any malicious packet that could be sent from specific host. IPS can be installed on SDN network that has centralized logic architecture, so that IPS doesnt need to be installed on lots of nodes instead it has to be installed alongside the controller as center of logic network. IPS still has a flaw and that is the block duration would remain the same no matter how often a specific host attacks. For this reason, writer would like to make a system that not only integrates IPS on the SDN, but also designs an adaptive IPS by utilizing a fuzzy logic that can decide how long blocks are based on the frequency variable and type of attacks. From the results of tests that have been done, SDN network that has been equipped with adaptive IPS has the ability to detect attacks and can block the attacker host with the duration based on the frequency and type of attacks. The final result obtained is to make the SDN network safer by adding 0.228 milliseconds as the execute time required for the fuzzy algorithm in one process. |
URL | https://ieeexplore.ieee.org/document/8528735 |
DOI | 10.1109/ICoICT.2018.8528735 |
Citation Key | pratama_design_2018 |
- logic architecture
- software-defined network
- software defined networking
- Software
- Servers
- security
- SDN network
- Resiliency
- resilience
- pubcrawl
- Metrics
- malicious packet
- logic network
- Adaptive Intrusion Prevention System
- IPS
- IP networks
- intrusion prevention system
- host attacks
- fuzzy set theory
- Fuzzy logic
- computer network security
- computer architecture
- attacker host
- attack prevention
- adaptive systems
- adaptive IPS