Towards An SDN Assisted IDS

Robert Sutton, Robert Ludwiniak, Nikolaos Pitropakis, Christos Chrysoulas, Tasos Dagiuklas

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

5 Citations (Scopus)

Abstract

Modern Intrusion Detection Systems are able to identify and check all traffic crossing the network segments that they are only set to monitor. Traditional network infrastructures use static detection mechanisms that check and monitor specific types of malicious traffic. To mitigate this potential waste of resources and improve scalability across an entire network, we propose a methodology which deploys distributed IDS in a Software Defined Network allowing them to be used for specific types of traffic as and when it appears on a network. The core of our work is the creation of an SDN application that takes input from a Snort IDS instances, thus working as a classifier for incoming network traffic with a static ruleset for those classifications. Our application has been tested on a virtualised platform where it performed as planned holding its position for limited use on static and controlled test environments.

Original languageEnglish
Title of host publication2021 11th IFIP International Conference on New Technologies, Mobility and Security, NTMS 2021
PublisherInstitute of Electrical and Electronics Engineers Inc.
ISBN (Electronic)9781665443999
DOIs
Publication statusPublished - 19 Apr 2021
Event11th IFIP International Conference on New Technologies, Mobility and Security, NTMS 2021 - Paris, France
Duration: 19 Apr 202121 Apr 2021

Publication series

Name2021 11th IFIP International Conference on New Technologies, Mobility and Security, NTMS 2021

Conference

Conference11th IFIP International Conference on New Technologies, Mobility and Security, NTMS 2021
Country/TerritoryFrance
CityParis
Period19/04/2121/04/21

Bibliographical note

Publisher Copyright:
© 2021 IEEE.

Keywords

  • IDS
  • Network Security
  • SDN

Cite this