J4 ›› 2015, Vol. 42 ›› Issue (1): 155-160.doi: 10.3969/j.issn.1001-2400.2015.01.025

• Original Articles • Previous Articles     Next Articles

Online traffic anomaly detection method for SDN

ZUO Qingyun;CHEN Ming;WANG Xiulei;LIU Bo   

  1. (College of Command Information Systems, PLA Univ. of Science and Technology, Nanjing  210007, China)
  • Received:2013-09-11 Online:2015-02-20 Published:2015-04-14
  • Contact: ZUO Qingyun E-mail:zuoqy@163.com

Abstract:

Based on the centralized control plane in SDN, an online traffic anomaly detection method (OpenTAD) is proposed. Firstly the flow table statistic is collected from the controller online, and the traffic matrix and sample entropy matrix are constructed and assembled. Then the PCA method is used to detect the abnormal traffic. The result of experiments show that, compared with the traditional PCA method which disposes the traffic matrix or the entropy matrix respectively offline, the OpenTAD is simple and effective, and traffic anomaly could be isolated rapidly. This method is a lightweight online traffic anomaly detection method for SDN.

Key words: OpenFlow network, software defined network, traffic anomaly, online detection, principal component analysis

CLC Number: 

  • TP393