TY - GEN
T1 - Quick Blocking Operation of IDS/SDN Cooperative Firewall Systems by Reducing Communication Overhead
AU - Takai, Akihiro
AU - Katsura, Yusei
AU - Yamai, Nariyoshi
AU - Nakagawa, Rei
AU - Visoottiviseth, Vasaka
N1 - Publisher Copyright:
© 2024 Global IT Research Institute - GIRI.
PY - 2024
Y1 - 2024
N2 - An Intrusion Detection System (IDS) / Software Defined Networking (SDN) cooperative firewall system has attracted much attention recently because it has many advantages of dynamic network configuration with SDN and scalable IDS hosts. In the IDS/SDN cooperative firewall system, an SDN switch relays traffic between a client and a server and mirrors traffic from a client to an IDS host. The IDS host monitors the mirrored traffic and notifies the SDN switch to block malicious traffic according to the detection of the attack. At this point, malicious packets reach the server until the IDS detects the attack and notifies it. In this paper, we propose a method to speed up mirroring and notification by integrating IDS and SDN switch hosts as a method to shorten the blocking time and compare it with existing methods. The experimental system was constructed using Raspberry Pi3 B+ and 4B boards. As a result, it was confirmed that the proposed method completes the blocking operation faster than the existing method. We also investigated the breakdown of the blocking time to confirm the effect of the proposed method.
AB - An Intrusion Detection System (IDS) / Software Defined Networking (SDN) cooperative firewall system has attracted much attention recently because it has many advantages of dynamic network configuration with SDN and scalable IDS hosts. In the IDS/SDN cooperative firewall system, an SDN switch relays traffic between a client and a server and mirrors traffic from a client to an IDS host. The IDS host monitors the mirrored traffic and notifies the SDN switch to block malicious traffic according to the detection of the attack. At this point, malicious packets reach the server until the IDS detects the attack and notifies it. In this paper, we propose a method to speed up mirroring and notification by integrating IDS and SDN switch hosts as a method to shorten the blocking time and compare it with existing methods. The experimental system was constructed using Raspberry Pi3 B+ and 4B boards. As a result, it was confirmed that the proposed method completes the blocking operation faster than the existing method. We also investigated the breakdown of the blocking time to confirm the effect of the proposed method.
KW - Firewall
KW - Intrusion Detection System
KW - OpenFlow
KW - Software Defined Network
UR - https://www.scopus.com/pages/publications/85189516646
U2 - 10.23919/ICACT60172.2024.10471925
DO - 10.23919/ICACT60172.2024.10471925
M3 - Conference contribution
AN - SCOPUS:85189516646
T3 - International Conference on Advanced Communication Technology, ICACT
SP - 1514
EP - 1520
BT - 26th International Conference on Advanced Communications Technology
PB - Institute of Electrical and Electronics Engineers Inc.
T2 - 26th International Conference on Advanced Communications Technology, ICACT 2024
Y2 - 4 February 2024 through 7 February 2024
ER -