Skip to main navigation Skip to search Skip to main content

Enabling dynamic network access control with anomaly-based IDS and SDN

  • Clemson University

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

53 Scopus citations

Abstract

In the Software Defined Networking (SDN) and Network Function Virtualization (NFV) era, it is critical to enable dynamic network access control. Traditionally, network access control policies are statically predefined as router entries or firewall rules. SDN enables more flexibility by re-actively installing flow rules into the switches to achieve dynamic network access control. However, SDN is limited in capturing network anomalies, which are usually important signs of security threats. In this paper, we propose to employ anomaly-based Intrusion Detection System (IDS) to capture network anomalies and generate SDN flow rules to enable dynamic network access control. We gain the knowledge of network anomalies from anomaly-based IDS by training an interpretable model to explain its outcome. Based on the explanation, we derive access control policies. We demonstrate the feasibility of our approach by explaining the outcome of an anomaly-based IDS built upon a Recurrent Neural Network (RNN) and generating SDN flow rules based on our explanation.

Original languageEnglish
Title of host publicationSDN-NFV 2019 - Proceedings of the ACM International Workshop on Security in Software Defined Networks and Network Function Virtualization, co-located with CODASPY 2019
PublisherAssociation for Computing Machinery
Pages13-16
Number of pages4
ISBN (Print)9781450361798
DOIs
StatePublished - Mar 19 2019
Event2019 ACM International Workshop on Security in Software Defined Networks and Network Function Virtualization, SDN-NFV Security 2019, co-located with CODASPY 2019 - Richardson, United States
Duration: Mar 27 2019Mar 27 2019

Publication series

NameSDN-NFV 2019 - Proceedings of the ACM International Workshop on Security in Software Defined Networks and Network Function Virtualization, co-located with CODASPY 2019

Conference

Conference2019 ACM International Workshop on Security in Software Defined Networks and Network Function Virtualization, SDN-NFV Security 2019, co-located with CODASPY 2019
Country/TerritoryUnited States
CityRichardson
Period03/27/1903/27/19

Keywords

  • Dynamic Access Control
  • IDS
  • SDN

Fingerprint

Dive into the research topics of 'Enabling dynamic network access control with anomaly-based IDS and SDN'. Together they form a unique fingerprint.

Cite this