An intelligent zero trust secure framework for software defined networking

Author:

Guo Xian,Xian Hongbo,Feng Tao,Jiang Yongbo,Zhang Di,Fang JunliORCID

Abstract

Software-defined networking (SDN) faces many of the same security threats as traditional networks. The separation of the SDN control plane and data plane makes the controller more vulnerable to cyber attacks. The conventional “perimeter defense” network security model cannot prevent lateral movement attacks caused by malicious insider users or hardware and software vulnerabilities. The “zero trust architecture” has become a new security network model to protect enterprise network security. In this article, we propose an intelligent zero-trust security framework IZTSDN for the software-defined networking by integrating deep learning and zero-trust architecture, which adopts zero-trust architecture to protect every resource and network connection in the network. IZTSDN uses a traffic anomaly detection mode CALSeq2Seql based on a deep learning algorithm to analyze users’ network behavior in real-time and achieve continuous tracking and analysis of users, restrict malicious users from accessing network resources, and realize the dynamic authorization process. Finally, the Mininet simulation platform is extended to build the simulation platform MiniIZTA supporting zero-trust architecture and the proposed security framework IZTSDN is experimentally analyzed. The experimental results show that the IZTSDN security framework can provide about 80.5% of throughput when the network is attacked. The accuracy of abnormal traffic detection reaches 99.56% on the SDN dataset, which verifies that the reliability and availability of the IZTSDN security framework are verified.

Funder

National Natural Science Foundation of China

Gansu Provincial Science and Technology Program Fund

Lanzhou University of Technology Graduate Program

Publisher

PeerJ

Subject

General Computer Science

Reference39 articles.

1. Automated DDOS attack detection in software defined networking;Ahuja;Journal of Network and Computer Applications,2021

2. The DDoS attacks detection through machine learning and statistical methods in SDN;Banitalebi Dehkordi;The Journal of Supercomputing,2021

3. Detecting and mitigating DDoS attacks in SDN using spatial-temporal graph convolutional network;Cao;IEEE Transactions on Dependable and Secure Computing,2021

4. An ecosystem for anomaly detection and mitigation in software-defined networking;Carvalho;Expert Systems with Applications,2018

5. Security in SDN: a comprehensive survey;Chica;Journal of Network and Computer Applications,2020

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3