Visible to the public Towards An SDN Assisted IDS

TitleTowards An SDN Assisted IDS
Publication TypeConference Paper
Year of Publication2021
AuthorsSutton, Robert, Ludwiniak, Robert, Pitropakis, Nikolaos, Chrysoulas, Christos, Dagiuklas, Tasos
Conference Name2021 11th IFIP International Conference on New Technologies, Mobility and Security (NTMS)
KeywordsIDS, Intrusion detection, Monitoring, Network security, pubcrawl, Resiliency, Scalability, SDN, SDN security, security, software defined networking, telecommunication traffic
AbstractModern Intrusion Detection Systems are able to identify and check all traffic crossing the network segments that they are only set to monitor. Traditional network infrastructures use static detection mechanisms that check and monitor specific types of malicious traffic. To mitigate this potential waste of resources and improve scalability across an entire network, we propose a methodology which deploys distributed IDS in a Software Defined Network allowing them to be used for specific types of traffic as and when it appears on a network. The core of our work is the creation of an SDN application that takes input from a Snort IDS instances, thus working as a classifier for incoming network traffic with a static ruleset for those classifications. Our application has been tested on a virtualised platform where it performed as planned holding its position for limited use on static and controlled test environments.
DOI10.1109/NTMS49979.2021.9432651
Citation Keysutton_towards_2021