Host independent and distributed detection system of the network attack by using OpenFlow

Ryosuke Miyazaki, Junpei Kawamoto, Shinichi Matsumoto, Kouichi Sakurai

Research output: Chapter in Book/Report/Conference proceedingConference contribution

Abstract

Recently, there are many types of cyber attacks and we should detect as many types as possible. In order to detect a wide variety of attacks, a complete distributed multi-Agent system is proposed. However, it requires the software installation in all hosts. The lack of resources also makes it hard to introduce the system to the devices. In this paper, we design a distributed defense algorithm employing a multi-Agent system. However, it is hard to detect the wide and shallow attacks such as horizontal portscan and if the systems is completely distributed. Therefore, we need to watch for the whole network in order to detect such attacks. Here, it is proposed to combine the system with OpenFlow which is suitable for having an overall network view. In general, however, OpenFlow has a central control system which is not scalable. Thus, we also propose to use several OpenFlow controllers and share information among them. By sharing information, we show that it is possible to detect a horizontal portscan.

Original languageEnglish
Title of host publication31st International Conference on Information Networking, ICOIN 2017
PublisherIEEE Computer Society
Pages236-241
Number of pages6
ISBN (Electronic)9781509051243
DOIs
Publication statusPublished - Apr 13 2017
Event31st International Conference on Information Networking, ICOIN 2017 - Da Nang, Viet Nam
Duration: Jan 11 2017Jan 13 2017

Publication series

NameInternational Conference on Information Networking
ISSN (Print)1976-7684

Other

Other31st International Conference on Information Networking, ICOIN 2017
Country/TerritoryViet Nam
CityDa Nang
Period1/11/171/13/17

All Science Journal Classification (ASJC) codes

  • Computer Networks and Communications
  • Information Systems

Fingerprint

Dive into the research topics of 'Host independent and distributed detection system of the network attack by using OpenFlow'. Together they form a unique fingerprint.

Cite this