Anomaly Detection in Software Defined Networking

Mehrnoosh Monshizadeh (Inventor), Vikramajeet Khatri (Inventor), Kimmo Kalervo Hatonen (Inventor), Aapo Kalliola (Inventor)

Research output: Patent

Abstract

A network apparatus of a communication system classifies (201) traffic flows containing packets based on packet features. The network apparatus provides (202) a copy of a packet contained in a traffic flow to a cluster node, and controls the cluster node to select (203) at least one detector node based on the features of the packet and to forward (204) said copy to the selected detector node to find out based on said copy whether the packet is malicious or not. In response to receiving (207) from the detector node a flow indication on the traffic flow, the network apparatus controls (209) a switch node to perform (210) at least one flow control action on the traffic flow, the action including one or more of flow removal, flow modification and flow installation.

Original languageEnglish
Patent numberEP3282665
IPCH04W 12/ 12 A I
Priority date10/08/2016
Publication statusPublished - 14 Feb 2018
MoE publication typeH1 Granted patent

Fingerprint

Dive into the research topics of 'Anomaly Detection in Software Defined Networking'. Together they form a unique fingerprint.

Cite this