Attack-Specific Feature Selection for Anomaly Detection in Software-Defined Networks

Due to the rapid advancement of technologies including the tremendous growth of multimedia content, cloud computing and mobile usage, conventional networks are not able to meet the demands. Software-Defined Networks (SDN) are considered one of the key enabling technologies providing a new powerful n...

Full description

Saved in:
Bibliographic Details
Main Author: Abbas, Nadine (author)
Other Authors: Nasser, Youssef (author), Shehab, Maryam (author), Sharafeddine, Sanaa (author)
Format: conferenceObject
Published: 2021
Online Access:http://hdl.handle.net/10725/14334
https://doi.org/10.1109/MENACOMM50742.2021.9678279
http://libraries.lau.edu.lb/research/laur/terms-of-use/articles.php
https://ieeexplore.ieee.org/abstract/document/9678279
Tags: Add Tag
No Tags, Be the first to tag this record!
Description
Summary:Due to the rapid advancement of technologies including the tremendous growth of multimedia content, cloud computing and mobile usage, conventional networks are not able to meet the demands. Software-Defined Networks (SDN) are considered one of the key enabling technologies providing a new powerful network architecture that allows the dynamic operation of different services using a common infrastructure. Despite their notable gains, SDNs may not be secure and are vulnerable to attacks. In this paper, we address the SDN vulnerabilities and present attack-specific feature selection to identify the features that have the most impact on anomaly detection. We first use the InSDN intrusion dataset that considers different attacks including Denial-of-Service (DoS), Distributed-DoS (DDoS), brute force, probe, web and botnet attacks. We then perform data pre-processing and apply univariate feature selection to select the features having the highest impact on the different attacks. These selected features can then be used to train the model which reduces the computational cost of modeling while keeping the high performance of the model. Detailed analysis and simulation results are then presented to show the predominant features and their impact on the different attacks.