Enhanced Intrusion Detection in Software-Defined Networking using Advanced Feature Selection: The EMRMR Approach
Received: 13 October 2024 | Revised: 3 November 2024 | Accepted: 5 November 2024 | Online: 2 December 2024
Corresponding author: Raed Basfar
Abstract
Most traditional IP networks face serious security and management challenges due to their rapid increase in complexity. SDN resolves these issues by the separation of control and data planes, hence enabling programmability for centralized management with flexibility. On the other hand, its centralized architecture makes SDN very prone to DDoS attacks, hence necessitating the use of advanced and efficient IDSs. This study focuses on improving IDS performance in SDN environments through the integration of deep learning techniques and novel feature selection methods. This study presents an Enhanced Maximum Relevance Minimum Redundancy (EMRMR) approach that incorporates a Mutual Information Feature Selection (MIFS) strategy and a new Contextual Redundancy Coefficient Upweighting (CRCU) strategy to optimize feature selection for early attack detection. Experiments on the inSDN dataset showed that EMRMR achieved better precision, recall, F1-score, and accuracy compared to the state-of-the-art approaches, especially when fewer features are selected. These results highlight the efficiency of the proposed EMRMR approach in the selection of relevant features with minimal computational overhead, which enhances the real-time capability for IDS in SDN environments.
Keywords:
software-defined networking, distributed denial of service, deep learning, enhanced maximum relevance minimum redundancy, mutual information feature selection, ntextual redundancy coefficient upweightingDownloads
References
Y. Maleh, Y. Qasmaoui, K. El Gholami, Y. Sadqi, and S. Mounir, "A comprehensive survey on SDN security: threats, mitigations, and future directions," Journal of Reliable Intelligent Environments, vol. 9, no. 2, pp. 201–239, Jun. 2023.
S. Mehraban and R. K. Yadav, "Traffic engineering and quality of service in hybrid software defined networks," China Communications, vol. 21, no. 2, pp. 96–121, Oct. 2024.
A. A. Bahashwan, M. Anbar, S. Manickam, T. A. Al-Amiedy, M. A. Aladaileh, and I. H. Hasbullah, "A Systematic Literature Review on Machine Learning and Deep Learning Approaches for Detecting DDoS Attacks in Software-Defined Networking," Sensors, vol. 23, no. 9, Jan. 2023, Art. no. 4441.
A. A. Najar and S. Manohar Naik, "Cyber-Secure SDN: A CNN-Based Approach for Efficient Detection and Mitigation of DDoS attacks," Computers & Security, vol. 139, Apr. 2024, Art. no. 103716.
M. A. Ambusaidi, X. He, P. Nanda, and Z. Tan, "Building an Intrusion Detection System Using a Filter-Based Feature Selection Algorithm," IEEE Transactions on Computers, vol. 65, no. 10, pp. 2986–2998, Jul. 2016.
R. Chaganti, W. Suliman, V. Ravi, and A. Dua, "Deep Learning Approach for SDN-Enabled Intrusion Detection System in IoT Networks," Information, vol. 14, no. 1, Jan. 2023, Art. no. 41.
J. C. Correa Chica, J. C. Imbachi, and J. F. Botero Vega, "Security in SDN: A comprehensive survey," Journal of Network and Computer Applications, 2020.
A. D. R. L. Ribeiro, R. Y. C. Santos, and A. C. A. Nascimento, "Anomaly Detection Technique for Intrusion Detection in SDN Environment using Continuous Data Stream Machine Learning Algorithms," in 2021 IEEE International Systems Conference (SysCon), Vancouver, Canada, Apr. 2021, pp. 1–7.
S. Zavrak and M. Iskefiyeli, "Flow-based intrusion detection on software-defined networks: a multivariate time series anomaly detection approach," Neural Computing and Applications, vol. 35, no. 16, pp. 12175–12193, Jun. 2023.
F. Amiri, M. Rezaei Yousefi, C. Lucas, A. Shakery, and N. Yazdani, "Mutual information-based feature selection for intrusion detection systems," Journal of Network and Computer Applications, vol. 34, no. 4, pp. 1184–1199, Jul. 2011.
M. Bennasar, Y. Hicks, and R. Setchi, "Feature selection using Joint Mutual Information Maximisation," Expert Systems with Applications, vol. 42, no. 22, pp. 8520–8532, Dec. 2015.
Z. Chkirbene, A. Erbad, R. Hamila, A. Mohamed, M. Guizani, and M. Hamdi, "TIDCS: A Dynamic Intrusion Detection and Classification System Based Feature Selection," IEEE Access, vol. 8, pp. 95864–95877, 2020.
G. Farahani, "Feature Selection Based on Cross-Correlation for the Intrusion Detection System," Security and Communication Networks, vol. 2020, no. 1, 2020, Art. no. 8875404.
D. Kshirsagar and S. Kumar, "Towards an intrusion detection system for detecting web attacks based on an ensemble of filter feature selection techniques," Cyber-Physical Systems, vol. 9, no. 3, pp. 244–259, Jul. 2023.
J. Maldonado, M. C. Riff, and B. Neveu, "A review of recent approaches on wrapper feature selection for intrusion detection," Expert Systems with Applications, vol. 198, Jul. 2022, Art. no. 116822.
M. A. Siddiqi and W. Pak, "Optimizing Filter-Based Feature Selection Method Flow for Intrusion Detection System," Electronics, vol. 9, no. 12, Dec. 2020, Art. no. 2114.
Z. Ling and Z. J. Hao, "An Intrusion Detection System Based on Normalized Mutual Information Antibodies Feature Selection and Adaptive Quantum Artificial Immune System," International Journal on Semantic Web and Information Systems (IJSWIS), vol. 18, no. 1, pp. 1–25, Jan. 2022.
N. Sultana, N. Chilamkurti, W. Peng, and R. Alhadad, "Survey on SDN based network intrusion detection system using machine learning approaches," Peer-to-Peer Networking and Applications, vol. 12, no. 2, pp. 493–501, Mar. 2019.
K. Muthamil Sudar and P. Deepalakshmi, "An intelligent flow-based and signature-based IDS for SDNs using ensemble feature selection and a multi-layer machine learning-based classifier," Journal of Intelligent & Fuzzy Systems, vol. 40, no. 3, pp. 4237–4256, Jan. 2021.
M. S. Elsayed, N. A. Le-Khac, and A. D. Jurcut, "InSDN: A Novel SDN Intrusion Dataset," IEEE Access, vol. 8, pp. 165263–165284, 2020.
T. Linhares, A. Patel, A. L. Barros, and M. Fernandez, "SDNTruth: Innovative DDoS Detection Scheme for Software-Defined Networks (SDN)," Journal of Network and Systems Management, vol. 31, no. 3, Jun. 2023, Art. no. 55.
J. Buzzio-García et al., "Exploring Traffic Patterns Through Network Programmability: Introducing SDNFLow, a Comprehensive OpenFlow-Based Statistics Dataset for Attack Detection," IEEE Access, vol. 12, pp. 42163–42180, 2024.
G. A. N. Segura, A. Chorti, and C. B. Margi, "Centralized and Distributed Intrusion Detection for Resource-Constrained Wireless SDN Networks," IEEE Internet of Things Journal, vol. 9, no. 10, pp. 7746–7758, Feb. 2022.
A. M. El-Shamy, N. A. El-Fishawy, G. Attiya, and M. A. A. Mohamed, "Anomaly Detection and Bottleneck Identification of The Distributed Application in Cloud Data Center using Software–Defined Networking," Egyptian Informatics Journal, vol. 22, no. 4, pp. 417–432, Dec. 2021.
M. H. H. Khairi, S. H. S. Ariffin, N. M. A. Latiff, A. S. Abdullah, and M. K. Hassan, "A Review of Anomaly Detection Techniques and Distributed Denial of Service (DDoS) on Software Defined Network (SDN)," Engineering, Technology & Applied Science Research, vol. 8, no. 2, pp. 2724–2730, Apr. 2018.
T. Jafarian, M. Masdari, A. Ghaffari, and K. Majidzadeh, "SADM-SDNC: security anomaly detection and mitigation in software-defined networking using C-support vector classification," Computing, vol. 103, no. 4, pp. 641–673, Apr. 2021.
J. Li, M. S. Othman, H. Chen, and L. M. Yusuf, "Optimizing IoT intrusion detection system: feature selection versus feature extraction in machine learning," Journal of Big Data, vol. 11, no. 1, Feb. 2024, Art. no. 36.
W. F. Urmi et al., "A stacked ensemble approach to detect cyber attacks based on feature selection techniques," International Journal of Cognitive Computing in Engineering, vol. 5, pp. 316–331, Jan. 2024.
S. Chakraborty, A. K. Turuk, and B. Sahoo, "Federated Learning enabled software-defined optical network with intelligent control plane architecture," Computers and Electrical Engineering, vol. 118, Aug. 2024, Art. no. 109329.
S. Yu et al., "FreeEM: Uncovering Parallel Memory EMR Covert Communication in Volatile Environments," in Proceedings of the 22nd Annual International Conference on Mobile Systems, Applications and Services, Tokyo, Japan, Jun. 2024, pp. 372–384.
P. Rajesh Kanna and P. Santhi, "Exploring the landscape of network security: a comparative analysis of attack detection strategies," Journal of Ambient Intelligence and Humanized Computing, vol. 15, no. 8, pp. 3211–3228, Aug. 2024.
M. A. Khadse and D. M. Dakhane, "A Review on Network Covert Channel Construction and Attack Detection," Concurrency and Computation: Practice and Experience, Art. no. e8316.
D. Kreutz, F. M. V. Ramos, P. E. Veríssimo, C. E. Rothenberg, S. Azodolmolky, and S. Uhlig, "Software-Defined Networking: A Comprehensive Survey," Proceedings of the IEEE, vol. 103, no. 1, pp. 14–76, Jan. 2015.
J. Li et al., "Feature Selection: A Data Perspective," ACM Computing Surveys, vol. 50, no. 6, pp. 1–45, Nov. 2018.
Q. Al-Tashi, S. J. Abdulkadir, H. M. Rais, S. Mirjalili, and H. Alhussian, "Approaches to Multi-Objective Feature Selection: A Systematic Literature Review," IEEE Access, vol. 8, pp. 125076–125096, 2020.
M. Labani, P. Moradi, and M. Jalili, "A multi-objective genetic algorithm for text feature selection using the relative discriminative criterion," Expert Systems with Applications, vol. 149, Jul. 2020, Art. no. 113276.
R. Gandhi, U. Ghose, and H. K. Thakur, "Revisiting Feature Ranking Methods using Information-Centric and Evolutionary Approaches: Survey," International Journal of Sensors Wireless Communications and Control, vol. 12, no. 1, pp. 5–18, Jan. 2022.
N. Hoque, H. A. Ahmed, D. K. Bhattacharyya, and J. K. Kalita, "A Fuzzy Mutual Information-based Feature Selection Method for Classification," Fuzzy Information and Engineering, vol. 8, no. 3, pp. 355–384, Sep. 2016.
P. A. Estevez, M. Tesmer, C. A. Perez, and J. M. Zurada, "Normalized Mutual Information Feature Selection," IEEE Transactions on Neural Networks, vol. 20, no. 2, pp. 189–201, Oct. 2009.
C. Suman, S. Tripathy, and S. Saha, "Building an Effective Intrusion Detection System using Unsupervised Feature Selection in Multi-objective Optimization Framework." arXiv, May 16, 2019.
B. A. Manjunatha, P. Gogoi, and M. T. Akkalappa, "Data Mining based Framework for Effective Intrusion Detection using Hybrid Feature Selection Approach," International Journal of Computer Network and Information Security, vol. 11, no. 8, pp. 1–12, Aug. 2019.
A. V. Turukmane and R. Devendiran, "M-MultiSVM: An efficient feature selection assisted network intrusion detection system using machine learning," Computers & Security, vol. 137, Feb. 2024, Art. no. 103587.
H. Peng, F. Long, and C. Ding, "Feature selection based on mutual information criteria of max-dependency, max-relevance, and min-redundancy," IEEE Transactions on Pattern Analysis and Machine Intelligence, vol. 27, no. 8, pp. 1226–1238, Dec. 2005.
M. S. E. Sayed, N. A. Le-Khac, M. A. Azer, and A. D. Jurcut, "A Flow-Based Anomaly Detection Approach With Feature Selection Method Against DDoS Attacks in SDNs," IEEE Transactions on Cognitive Communications and Networking, vol. 8, no. 4, pp. 1862–1880, Sep. 2022.
L. Zhang, K. Liu, X. Xie, W. Bai, B. Wu, and P. Dong, "A data-driven network intrusion detection system using feature selection and deep learning," Journal of Information Security and Applications, vol. 78, Nov. 2023, Art. no. 103606.
Downloads
How to Cite
License
Copyright (c) 2024 Raed Basfar, Mohamed Y. Dahab, Abdullah Marish Ali, Fathy Eassa, Kholoud Bajunaied
This work is licensed under a Creative Commons Attribution 4.0 International License.
Authors who publish with this journal agree to the following terms:
- Authors retain the copyright and grant the journal the right of first publication with the work simultaneously licensed under a Creative Commons Attribution License that allows others to share the work with an acknowledgement of the work's authorship and initial publication in this journal.
- Authors are able to enter into separate, additional contractual arrangements for the non-exclusive distribution of the journal's published version of the work (e.g., post it to an institutional repository or publish it in a book), with an acknowledgement of its initial publication in this journal.
- Authors are permitted and encouraged to post their work online (e.g., in institutional repositories or on their website) after its publication in ETASR with an acknowledgement of its initial publication in this journal.