Quick Blocking Operation of Firewall System Cooperating with IDS and SDN

dc.contributor.authorKatsura Y.
dc.contributor.authorSakarin P.
dc.contributor.authorYamai N.
dc.contributor.authorKimiyama H.
dc.contributor.authorVisoottiviseth V.
dc.contributor.otherMahidol University
dc.date.accessioned2023-06-18T17:13:00Z
dc.date.available2023-06-18T17:13:00Z
dc.date.issued2022-01-01
dc.description.abstractFirewalls, intrusion detection systems (IDSs), and intrusion prevention systems (IPSs) are normally used to filter anomaly traffic and prevent attacks from the Internet. However, preconfiguring firewalls and IDS on multiple devices is an exhausting work for the network administrators. Software Defined Network (SDN) is the concept proposed to make the network management easier by using an SDN controller and SDN switches. In this research, we propose a system that integrates IDS together with SDN in order to block anomaly traffic in a fast manner. Once the IDS detects anomaly traffic, it will send an alert message back to the SDN switch. Then, this alert message will be sent as a PacketIn message to the SDN controller in order to set up rules to block the attack. To evaluate our system, we conduct experiments to compare the performance of our proposed system using syslog and Socket API with the existing method that uses REST API, and another comparison method, in term of processing time. Our experiment results confirm that our proposed method can result in the smaller latency and can quickly block malicious traffic.
dc.identifier.citationInternational Conference on Advanced Communication Technology, ICACT Vol.2022-February (2022) , 393-398
dc.identifier.doi10.23919/ICACT53585.2022.9728831
dc.identifier.issn17389445
dc.identifier.scopus2-s2.0-85127515663
dc.identifier.urihttps://repository.li.mahidol.ac.th/handle/20.500.14594/84644
dc.rights.holderSCOPUS
dc.subjectEngineering
dc.titleQuick Blocking Operation of Firewall System Cooperating with IDS and SDN
dc.typeConference Paper
mu.datasource.scopushttps://www.scopus.com/inward/record.uri?partnerID=HzOxMe3b&scp=85127515663&origin=inward
oaire.citation.endPage398
oaire.citation.startPage393
oaire.citation.titleInternational Conference on Advanced Communication Technology, ICACT
oaire.citation.volume2022-February
oairecerif.author.affiliationNara Institute of Science and Technology
oairecerif.author.affiliationDaido University
oairecerif.author.affiliationMahidol University
oairecerif.author.affiliationTokyo University of Agriculture and Technology

Files

Collections