TY - GEN
T1 - Enabling dynamic network access control with anomaly-based IDS and SDN
AU - Li, Hongda
AU - Wei, Feng
AU - Hu, Hongxin
N1 - Publisher Copyright:
© 2019 Association for Computing Machinery.
PY - 2019/3/19
Y1 - 2019/3/19
N2 - In the Software Defined Networking (SDN) and Network Function Virtualization (NFV) era, it is critical to enable dynamic network access control. Traditionally, network access control policies are statically predefined as router entries or firewall rules. SDN enables more flexibility by re-actively installing flow rules into the switches to achieve dynamic network access control. However, SDN is limited in capturing network anomalies, which are usually important signs of security threats. In this paper, we propose to employ anomaly-based Intrusion Detection System (IDS) to capture network anomalies and generate SDN flow rules to enable dynamic network access control. We gain the knowledge of network anomalies from anomaly-based IDS by training an interpretable model to explain its outcome. Based on the explanation, we derive access control policies. We demonstrate the feasibility of our approach by explaining the outcome of an anomaly-based IDS built upon a Recurrent Neural Network (RNN) and generating SDN flow rules based on our explanation.
AB - In the Software Defined Networking (SDN) and Network Function Virtualization (NFV) era, it is critical to enable dynamic network access control. Traditionally, network access control policies are statically predefined as router entries or firewall rules. SDN enables more flexibility by re-actively installing flow rules into the switches to achieve dynamic network access control. However, SDN is limited in capturing network anomalies, which are usually important signs of security threats. In this paper, we propose to employ anomaly-based Intrusion Detection System (IDS) to capture network anomalies and generate SDN flow rules to enable dynamic network access control. We gain the knowledge of network anomalies from anomaly-based IDS by training an interpretable model to explain its outcome. Based on the explanation, we derive access control policies. We demonstrate the feasibility of our approach by explaining the outcome of an anomaly-based IDS built upon a Recurrent Neural Network (RNN) and generating SDN flow rules based on our explanation.
KW - Dynamic Access Control
KW - IDS
KW - SDN
UR - https://www.scopus.com/pages/publications/85066147143
U2 - 10.1145/3309194.3309199
DO - 10.1145/3309194.3309199
M3 - Conference contribution
AN - SCOPUS:85066147143
SN - 9781450361798
T3 - SDN-NFV 2019 - Proceedings of the ACM International Workshop on Security in Software Defined Networks and Network Function Virtualization, co-located with CODASPY 2019
SP - 13
EP - 16
BT - SDN-NFV 2019 - Proceedings of the ACM International Workshop on Security in Software Defined Networks and Network Function Virtualization, co-located with CODASPY 2019
PB - Association for Computing Machinery
T2 - 2019 ACM International Workshop on Security in Software Defined Networks and Network Function Virtualization, SDN-NFV Security 2019, co-located with CODASPY 2019
Y2 - 27 March 2019 through 27 March 2019
ER -