用混合机器学习检测SDN中隐蔽的交换机负载谎报,防止沉浸式应用质量崩溃
Detection of Misreporting Attacks on Software-Defined Immersive Environments
- 结合无监督异常评分与有监督分类,识别交换机报告负载的时间不一致性
- 在真实测试床下实现高召回率,有效检测恶意负载谎报行为
- 适合需要高可靠性的沉浸式网络应用安全防护人员参考
利用可编程中间件集中控制网络基础设施的能力,使软件定义网络(SDN)成为沉浸式环境等新兴应用的理想选择。然而,这种灵活性引入了新漏洞,如交换机负载谎报导致的负载不均,进而使沉浸式环境面临严重质量下降风险。本文提出一种基于混合机器学习的网络异常检测框架,通过捕捉交换机报告负载的时间不一致性,识别此类隐蔽的谎报行为,从而防范托管沉浸式应用可能发生的灾难性质量退化。该系统融合无监督异常评分与有监督分类,以稳健区分恶意行为。实验基于真实测试床部署,在正常和攻击条件下收集数据用于模型训练与评估。结果表明,该框架在检测负载谎报行为时具备高召回率,适用于SDN环境中早期且可靠的检测。
原文摘要 · Abstract (English)
The ability to centrally control network infrastructure using a programmable middleware has made Software-Defined Networking (SDN) ideal for emerging applications, such as immersive environments. However, such flexibility introduces new vulnerabilities, such as switch misreporting led load imbalance, which in turn make such immersive environment vulnerable to severe quality degradation. In this paper, we present a hybrid machine learning (ML)-based network anomaly detection framework that identifies such stealthy misreporting by capturing temporal inconsistencies in switch-reported loads, and thereby counter potentially catastrophic quality degradation of hosted immersive application. The detection system combines unsupervised anomaly scoring with supervised classification to robustly distinguish malicious behavior. Data collected from a realistic testbed deployment under both benign and adversarial conditions is used to train and evaluate the model. Experimental results show that the framework achieves high recall in detecting misreporting behavior, making it effective for early and reliable detection in SDN environments.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。