Détails Publication
ARTICLE

Toward an Operational Intrusion Detection and Prevention System for SDN-IoT: A Cascaded Deep Learning Approach with Automatic Mitigation

  • Journal of Xidian University Journal of Xidian University , Issue 6 (20) : 761-775
Discipline : Informatique et sciences de l'information
Auteur(s) :
Renseignée par : OUATTARA Yacouba

Résumé

Abstract—The convergence of software-defined networking and the Internet of Things widens the attack surface of connected networks
and calls for defenses able to detect attacks at the controller's vantage point and to block them there. Earlier work compared deep
architectures for denial-of-service attack detection and opened two perspectives: extension to the multiclass setting and integration into an
operational intrusion detection and prevention system acting in real time. This article takes up these perspectives in an SDN-IoT context.
On ASEADOS-SDN-IoT, a recent dataset that synchronizes device traffic with controller telemetry, we evaluate a deep detector organized
as a two-stage cascade covering five traffic classes, comparing six architectures at each stage. The hybrid CNN-BiLSTM network offers
the best trade-off, and the cascade outperforms a direct multiclass classifier evaluated under identical conditions. We then integrate this
detector into a Ryu controller: the sixty-three features are reconstructed online, the cascade decides at every cycle, and a targeted
OpenFlow mitigation blocks the attack source after hysteresis confirmation. A functional demonstration on four attack scenarios and a
deployability analysis of the full online feature set complete the study. The results delineate both the scope and the limits of the system.

Mots-clés

Cybersecurity; deep learning; intrusion detection and prevention system (IDPS); software-defined networking (SDN); Internet of Things (IoT); mitigation; cascaded classification; ASEADOS-SDN-IoT.

1053
Enseignants
10709
Publications
49
Laboratoires
129
Projets