Real-Time Malicious Traffic Detection With Online Isolation Forest Over SD-WAN

Pei Zhang,Fangzhou He,Han Zhang,Jiankun Hu,Xiaohong Huang,Jilong Wang,Xia Yin,Huahong Zhu,Yahui Li
DOI: https://doi.org/10.1109/tifs.2023.3262121
IF: 7.231
2023-04-08
IEEE Transactions on Information Forensics and Security
Abstract:Software Defined Network (SDN) has been widely used in modern network architecture. The SD-WAN is considered as a technology that has a potential to revolutionize the WAN service usage by utilizing the SDN philosophy. Attacks within SD-WAN can affect the network and block the entire services. In this paper, we propose a machine learning based anomalous traffic detection framework named OADSD over SD-WAN that can achieve task independently and has the ability of adapting to the environment. The OADSD adopts Distributed Dynamic Feature Extraction (DDFE) to extract representative features directly from the raw traffic, and proposes the On-demand Evolving Isolation Forest (OEIF) to make the system adapt to an environment. We provide a theoretical analysis of the performance of the OADSD. We also conduct comprehensive experiments to evaluate the performance of the OADSD with real world public datasets as well as a small real testbed. Our experiments under real world public datasets show that, the OADSD can accurately detect various kinds of attacks with a high performance. Compared with the state-of-the-art systems, the OADSD can achieve up to 60% accuracy improvement.
computer science, theory & methods,engineering, electrical & electronic
What problem does this paper attempt to address?