• DocumentCode
    3748391
  • Title

    Network intrusion detection and prevention middlebox management in SDN

  • Author

    Wen Wang; Wenbo He; Jinshu Su

  • Author_Institution
    School of Computer Science, McGill University, Montreal, QC, Canada
  • fYear
    2015
  • Firstpage
    1
  • Lastpage
    8
  • Abstract
    In traditional networks, it is difficult to manage the distributed detection and prevention nodes of IDS and IPS due to the laborious manual deployment and independent configuration. Software defined networking (SDN) provides a flexible approach to control the underlying network infrastructures efficiently. However, the OpenFlow flow table is too simple to provide complex functions with the match-action style processing. To support more functionalities, in this paper, we propose a middlebox management architecture with SDN - OpenMiddlebox, by extending OpenFlow to support middleboxes with ClickOS virtual machines (VM), so that programmable middleboxes could be deployed and managed in switches with fast booted ClickOS VMs flexibly. We then design automatic deployment and update schemes of network intrusion detection and prevention middleboxes with the centralized controller. The evaluation results show that OpenMiddlebox could manage the distributed middleboxes efficiently and is scalable to large networks, and the centralized control also improves the network intrusion detection and prevention accuracy.
  • Keywords
    "Middleboxes","Control systems","Intrusion detection","Computer architecture","Protocols","Manuals","Network topology"
  • Publisher
    ieee
  • Conference_Titel
    Computing and Communications Conference (IPCCC), 2015 IEEE 34th International Performance
  • Electronic_ISBN
    2374-9628
  • Type

    conf

  • DOI
    10.1109/PCCC.2015.7410312
  • Filename
    7410312