4.4 SDN Management 81
customer accounting, and anomaly detection. Today, statistics of
traffic flows are reported by the routers to the centralized management
system. Thus, the impact of network measurement on the network
must be minimized. For example, an aggressive monitoring may result
in artificial bottlenecks in the network. With too passive a scheme,
it may miss important events. Thus, the key challenge is to strike a
careful balance between effectiveness (supporting a wide range of
applications with accurate statistics) and efficiency (intruding low
overhead and cost). Among all the network management applications,
from the security perspective, one important question to be answered
is how to count flows to provide sufficient information for the network
anomaly detection?
Existing attempts to achieve a better overhead/accuracy balance is
through traffic sampling [85], that is, a router selectively records packets or flows randomly with a preconfigured sampling rate. The thinned
traffic is then fed as input to anomaly detection. While being widely
deployed as they are simple to implement with low CPU power and
memory requirements, studies have shown it to be inaccurate, as it is
likely to miss small flows entirely.
The network flow measurement should provide a more flexible and
more interactive interface to the anomaly detectors so that the set of
flows collected can be dynamically adjusted according to the findings
of anomaly detector immediately. There are twofold benefits of such
interfaces. On the one hand, the anomaly detector can instruct the
flow collection module to provide finer-granularity data once there is
a suspicion of attacks, so that the anomaly can be identified sooner.
On the other hand, it can inform to collect coarser-grained flow data
both spatially and temporally when there is no sign of attacks such
that the traffic monitoring load is reduced. Therefore, this adaptive
interface can simultaneously improve the accuracy and reduce the
overhead.
SDN has two key features that enable the design of a flexible flow
counting API for anomaly detection. On the one hand, SDN breaks
the tight bindings between forwarding and counting. One can install
separate wildcard rules on OpenFlow (OF) switches purely for monitoring purposes, which offers tremendous flexibility in defining the set
of packets to count. On the other hand, thanks to the simple interface
between control and forwarding plane, one can easily adjust the elements to count, by simply updating the counting rules. This property
makes real-time adaptive counting possible.
customer accounting, and anomaly detection. Today, statistics of
traffic flows are reported by the routers to the centralized management
system. Thus, the impact of network measurement on the network
must be minimized. For example, an aggressive monitoring may result
in artificial bottlenecks in the network. With too passive a scheme,
it may miss important events. Thus, the key challenge is to strike a
careful balance between effectiveness (supporting a wide range of
applications with accurate statistics) and efficiency (intruding low
overhead and cost). Among all the network management applications,
from the security perspective, one important question to be answered
is how to count flows to provide sufficient information for the network
anomaly detection?
Existing attempts to achieve a better overhead/accuracy balance is
through traffic sampling [85], that is, a router selectively records packets or flows randomly with a preconfigured sampling rate. The thinned
traffic is then fed as input to anomaly detection. While being widely
deployed as they are simple to implement with low CPU power and
memory requirements, studies have shown it to be inaccurate, as it is
likely to miss small flows entirely.
The network flow measurement should provide a more flexible and
more interactive interface to the anomaly detectors so that the set of
flows collected can be dynamically adjusted according to the findings
of anomaly detector immediately. There are twofold benefits of such
interfaces. On the one hand, the anomaly detector can instruct the
flow collection module to provide finer-granularity data once there is
a suspicion of attacks, so that the anomaly can be identified sooner.
On the other hand, it can inform to collect coarser-grained flow data
both spatially and temporally when there is no sign of attacks such
that the traffic monitoring load is reduced. Therefore, this adaptive
interface can simultaneously improve the accuracy and reduce the
overhead.
SDN has two key features that enable the design of a flexible flow
counting API for anomaly detection. On the one hand, SDN breaks
the tight bindings between forwarding and counting. One can install
separate wildcard rules on OpenFlow (OF) switches purely for monitoring purposes, which offers tremendous flexibility in defining the set
of packets to count. On the other hand, thanks to the simple interface
between control and forwarding plane, one can easily adjust the elements to count, by simply updating the counting rules. This property
makes real-time adaptive counting possible.
