SHA-256-Enabled Lightweight Hybrid Intrusion Prevention System for SDN–IoT Networks
摘要
The cyber-attacks have become more powerful and more frequent in software-defined network (SDN) and Internet of Things (IoT) environments due to which the old intrusion prevention systems (IPSs) are finding it difficult to establish an equilibrium among accuracy, speed, and resource utilization. The authors of this paper present a lightweight hybrid IPS that fuses the SHA-256 cryptographic hash matching with a decision tree fall back classifier for the real-time and accurate detection of cyber threats. The system quickly allocates network traffic by generating a hash of the chosen flow features and then comparing it with the reference sets of the benign and the malicious. In case of a mismatch, the fall-back model based on machine learning is triggered, thus allowing the threat detection to be continuous along with being adaptive. To show that the method is not limited to a certain dataset, they use two benchmark databases—NSL-KDD and CIC-IDS-2017. Research findings demonstrate that proposed system as evaluated with the CIC-IDS-2017 database excels, obtaining 97.19