
An Intrusion Prevention Scheme for Malicious Network Traffic Based on SDN
Author(s) -
Xiaofeng Xu,
Jiahao Dai,
Yifang Zhi
Publication year - 2020
Publication title -
iop conference series. materials science and engineering
Language(s) - English
Resource type - Journals
eISSN - 1757-899X
pISSN - 1757-8981
DOI - 10.1088/1757-899x/790/1/012030
Subject(s) - computer science , scheme (mathematics) , intrusion detection system , computer network , network packet , key (lock) , controller (irrigation) , network security , computer security , mathematical analysis , mathematics , agronomy , biology
In recent years, SDN technology has developed rapidly, and the security of SDN is the key to its further development and application. Intrusion prevention system possesses both the features of intrusion detection and protection, which is one of the important methods to ensure the security of SDN network. In this paper, we proposed a SDN-based intrusion prevention scheme for SDN security. The scheme utilizes the programmability of SDN to create four modules on the application plane of the controller, including the network monitoring module, IP address detection module, destructive packets detection and Snort linkage module. The scheme also provides users with Web UI and manual/automatic operation mode. Finally, we deployed the scheme on the Mininet platform with the Floodlight controller.