Back to Search
Start Over
Network-Wide Forwarding Anomaly Detection and Localization in Software Defined Networks
- Source :
- IEEE/ACM Transactions on Networking. 29:332-345
- Publication Year :
- 2021
- Publisher :
- Institute of Electrical and Electronics Engineers (IEEE), 2021.
-
Abstract
- A crucial requirement for Software Defined Network (SDN) is that data plane forwarding behaviors should always agree with control plane policies. Such requirement cannot be met when there are forwarding anomalies , where packets deviate from the paths specified by the controller. Most anomaly detection methods for SDN install dedicated rules to collect statistics of each flow, and check whether the statistics conform to the “flow conservation principle”. We find these methods have a limited detection scope: they look at one flow each time, thus can only check a small number of flows simultaneously. In addition, dedicated rules for statistics collection can impose a large overhead on flow tables of SDN switches. To this end, this paper presents FOCES, a network-wide forwarding anomaly detection and localization method in SDN. Different from previous methods, FOCES applies a new kind of flow conservation principle at network wide, and can check forwarding behaviors of all flows in the network simultaneously, without installing any dedicated rules. Finally, FOCES applies a voting-based method to localize malicious switches when anomalies are detected. Experiments with four network topologies show that FOCES can achieve a detection precision higher than 90%, when the packet loss rate is no larger than 10%, and a localization accuracy of around 80% when the packet loss rate is no larger than 5%.
- Subjects :
- Computer Networks and Communications
business.industry
Network packet
Computer science
020206 networking & telecommunications
02 engineering and technology
Network topology
Computer Science Applications
Control theory
Packet loss
0202 electrical engineering, electronic engineering, information engineering
Forwarding plane
Overhead (computing)
Anomaly detection
Electrical and Electronic Engineering
Routing control plane
business
Software-defined networking
Software
Computer network
Subjects
Details
- ISSN :
- 15582566 and 10636692
- Volume :
- 29
- Database :
- OpenAIRE
- Journal :
- IEEE/ACM Transactions on Networking
- Accession number :
- edsair.doi...........0486a7565ecd5cda5d02729a90f94ecd