Publications

Detailed Information

Information Entropy based Network Anomaly Detection in Software-Defined Networking : SDN에서의 정보 엔트로피를 활용한 네트워크 이상 상황 탐지

DC Field Value Language
dc.contributor.advisor김종권-
dc.contributor.author김나언-
dc.date.accessioned2018-05-29T03:32:32Z-
dc.date.available2018-05-29T03:32:32Z-
dc.date.issued2018-02-
dc.identifier.other000000150239-
dc.identifier.urihttps://hdl.handle.net/10371/141555-
dc.description학위논문 (석사)-- 서울대학교 대학원 : 공과대학 컴퓨터공학부, 2018. 2. 김종권.-
dc.description.abstractDue to the spread of various smart devices and concomitant rise of network traffic rate, the importance of network infrastructure to accommodate them is increasing. As the network environment changes, a flexible and efficient network infrastructure that can easily deal with this has become necessary. So, Software-Defined Networking (SDN) has gained a lot of attention in recent years. SDN separates the physical forwarding function and logical control function of the network, and it centrally controls the network via API. However, the centralized control and programmable characteristics bring a lot of security issues. To mitigate security threats in SDN, many researchers have tried to monitor network traffic. Particularly to monitor SDN network, they collect flow statistics from the OpenFlow switches and detect network anomalies in the controller. But when the network scale becomes large, the flow statistics collecting process burdens the communication between the OpenFlow switches and the controller. In this thesis, we design a flow aggregation module in the OpenFlow switch based on the flow-based nature of SDN. This lightens the controller's overhead caused by the flow statistics collecting process and achieves a distributed flow statistics collection in SDN. In view of computing overhead and scalability, we apply information entropy to monitor and detect network anomalies in the controller. Information entropy is an important concept of information theory, which is a measure of the uncertainty or randomness associated with data. We prove the practicality of proposed network anomaly detection mechanism by using real legitimate and malicious traffic traces. The proposed mechanism achieves a high detection accuracy with a low false positive rate and significantly improves CPU utilization, compared with previous work.-
dc.description.tableofcontentsCHAPTER Ⅰ: Introduction 1
CHAPTER Ⅱ: Background 4
CHAPTER Ⅲ: Related Work 7
CHAPTER Ⅳ: Analysis of Network Anomalies 9
4.1 Network Anomaly Detection 9
4.2 DDoS 10
4.3 Hostscan and Portscan 10
CHAPTER Ⅴ: Proposed Mechanism 13
5.1 Adversary Model 13
5.2 Information Entropy based Network Anomaly Detection in SDN 15
5.3 Flow Aggregation 16
5.4 Anomaly Detection 18
5.5 Anomaly Mitigation 20
CHAPTER Ⅵ: Evaluation 21
6.1 Experiment Setup 21
6.2 Network Traffic Dataset 22
6.3 Performance Analysis 23
CHAPTER Ⅶ: Conclusion 31
BIBLIOGRAPHY 32
초록 35
-
dc.formatapplication/pdf-
dc.format.extent990801 bytes-
dc.format.mediumapplication/pdf-
dc.language.isoen-
dc.publisher서울대학교 대학원-
dc.subjectSoftware Defined Networking-
dc.subjectSDN-
dc.subjectNetwork Anomaly Detection-
dc.subjectNetwork Traffic Monitoring-
dc.subjectInformation Entropy-
dc.subjectNetwork Security-
dc.subject.ddc621.39-
dc.titleInformation Entropy based Network Anomaly Detection in Software-Defined Networking-
dc.title.alternativeSDN에서의 정보 엔트로피를 활용한 네트워크 이상 상황 탐지-
dc.typeThesis-
dc.contributor.AlternativeAuthorKim Na Eon-
dc.description.degreeMaster-
dc.contributor.affiliation공과대학 컴퓨터공학부-
dc.date.awarded2018-02-
Appears in Collections:
Files in This Item:

Altmetrics

Item View & Download Count

  • mendeley

Items in S-Space are protected by copyright, with all rights reserved, unless otherwise indicated.

Share