The Study on the Blocking Time Reduction of the IDS/SON Cooperative Firewall System

dc.contributor.authorNimitkul P.
dc.contributor.authorTakai A.
dc.contributor.authorYamai N.
dc.contributor.authorNakagawa R.
dc.contributor.authorTeerakanok S.
dc.contributor.correspondenceNimitkul P.
dc.contributor.otherMahidol University
dc.date.accessioned2024-03-13T18:21:02Z
dc.date.available2024-03-13T18:21:02Z
dc.date.issued2023-01-01
dc.description.abstractThis research introduces a method to reduce the mean time-To-respond of the Intrusion detection system (IDS) / software-defined network (SDN) cooperative firewall system to increase its efficiency. The previous IDS/SDN Cooperative firewall system relies on Syslog events to pass the message between the SDN controller, IDS, and Open Virtual Switch (OvS) to alter the flow entries. This, however, was proven to be too slow in blocking some malicious packets. This new study aims to improve the blocking delay in two ways: by integrating the IDS with the Open Virtual Switch, and by adding multiple IDS cores to it. By integrating the IDS into the OvS, the study has found that the blocking speed has increased significantly, approximately 7 times faster since there is no communication overhead. This, however, might lower the flexibility of the SDN system since the IDS is now attached to OvS itself. The configuration is explored further by adding another IDS instance to the device running the OvS to create a dual-core IDS system. This configuration is proven to increase the efficiency of the IDS/SDN cooperative firewall when under high load. However, it is slower than the former single-core IDS when under normal load due to the communication overhead.
dc.identifier.citationProceedings - 2023 IEEE 23rd International Conference on Software Quality, Reliability, and Security Companion, QRS-C 2023 (2023) , 549-554
dc.identifier.doi10.1109/QRS-C60940.2023.00095
dc.identifier.scopus2-s2.0-85186747957
dc.identifier.urihttps://repository.li.mahidol.ac.th/handle/20.500.14594/97555
dc.rights.holderSCOPUS
dc.subjectComputer Science
dc.subjectEngineering
dc.titleThe Study on the Blocking Time Reduction of the IDS/SON Cooperative Firewall System
dc.typeConference Paper
mu.datasource.scopushttps://www.scopus.com/inward/record.uri?partnerID=HzOxMe3b&scp=85186747957&origin=inward
oaire.citation.endPage554
oaire.citation.startPage549
oaire.citation.titleProceedings - 2023 IEEE 23rd International Conference on Software Quality, Reliability, and Security Companion, QRS-C 2023
oairecerif.author.affiliationMahidol University
oairecerif.author.affiliationTokyo University of Agriculture and Technology

Files

Collections