A Machine-Learning-Based Cyberattack Detector for a Cloud-Based SDN Controller
-
Published:2023-04-13
Issue:8
Volume:13
Page:4914
-
ISSN:2076-3417
-
Container-title:Applied Sciences
-
language:en
-
Short-container-title:Applied Sciences
Author:
Mozo Alberto1ORCID, Karamchandani Amit1ORCID, de la Cal Luis1ORCID, Gómez-Canaval Sandra1ORCID, Pastor Antonio2ORCID, Gifre Lluis3ORCID
Affiliation:
1. ETSI Sistemas Informáticos, Departamento Sistemas Informáticos, Universidad Politécnica de Madrid, 28031 Madrid, Spain 2. Telefónica I+D, 28050 Madrid, Spain 3. Centre Tecnològic de Telecomunicacions de Catalunya (CTTC/CERCA), 08860 Castelldefels, Spain
Abstract
The rapid evolution of network infrastructure through the softwarization of network elements has led to an exponential increase in the attack surface, thereby increasing the complexity of threat protection. In light of this pressing concern, European Telecommunications Standards Institute (ETSI) TeraFlowSDN (TFS), an open-source microservice-based cloud-native Software-Defined Networking (SDN) controller, integrates robust Machine-Learning components to safeguard its network and infrastructure against potential malicious actors. This work presents a comprehensive study of the integration of these Machine-Learning components in a distributed scenario to provide secure end-to-end protection against cyber threats occurring at the packet level of the telecom operator’s Virtual Private Network (VPN) services configured with that feature. To illustrate the effectiveness of this integration, a real-world emerging attack vector (the cryptomining malware attack) is used as a demonstration. Furthermore, to address the pressing challenge of energy consumption in the telecom industry, we harness the full potential of state-of-the-art Green Artificial Intelligence techniques to optimize the size and complexity of Machine-Learning models in order to reduce their energy usage while maintaining their ability to accurately detect potential cyber threats. Additionally, to enhance the integrity and security of TeraFlowSDN’s cybersecurity components, Machine-Learning models are safeguarded from sophisticated adversarial attacks that attempt to deceive them by subtly perturbing input data. To accomplish this goal, Machine-Learning models are retrained with high-quality adversarial examples generated using a Generative Adversarial Network.
Funder
European Union’s Horizon 2020 Research and Innovation Programme Horizon Europe SNS R&I Work Programme
Subject
Fluid Flow and Transfer Processes,Computer Science Applications,Process Chemistry and Technology,General Engineering,Instrumentation,General Materials Science
Reference52 articles.
1. A survey on the security of stateful SDN data planes;Dargahi;IEEE Commun. Surv. Tutor.,2017 2. Vilalta, R., Munoz, R., Casellas, R., Martínez, R., López, V., de Dios, O.G., Pastor, A., Katsikas, G.P., Klaedtke, F., and Monti, P. (2021, January 8–11). Teraflow: Secured autonomic traffic management for a tera of sdn flows. Proceedings of the 2021 Joint European Conference on Networks and Communications & 6G Summit (EuCNC/6G Summit), Porto, Portugal. 3. Dahmen-Lhuissier, S. (2023, April 04). TFS. Available online: https://www.etsi.org/committee/2064-tfs. 4. NFV: Security threats and best practices;Lal;IEEE Commun. Mag.,2017 5. Xing, T., Xiong, Z., Huang, D., and Medhi, D. (2014, January 17–21). SDNIPS: Enabling Software-Defined Networking based intrusion prevention system in clouds. Proceedings of the tenth International Conference on Network and Service Management (CNSM) and Workshop, Rio de Janeiro, Brazil.
Cited by
7 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献
|
|