DOI: 10.3390/fi18080415 ISSN: 1999-5903

SDN-Enabled Digital Twin Networks Architecture for Proactive Detection and Mitigation of Malicious Encrypted Traffic

Xavier Hesselbach, Juan Parada Claro

Classification algorithms for encrypted traffic are an effective means of improving the security of private networks. However, they operate a posteriori because they require collecting flow level features (packet length, inter-arrival time, and flow identifiers), which can only be extracted after observing multiple packets before reaching a classification decision. Furthermore, to achieve accurate classification, the analyzed flows must be processed by the target server or by a server that faithfully replicates its behavior. This paper proposes a Digital Twin Network (DTN) architecture to prevent unknown traffic from being initially processed by the Original Network, thereby reducing the risk of attacks that cannot be immediately detected by encrypted traffic classification. The architecture integrates SDN and P4 to implement the monitoring and traffic redirection required by the DTN, and a proof-of-concept prototype is presented to validate its functionality. This work identifies a trade-off regarding access to previously unknown external services due to redirection via the DTN until classification is complete, which can introduce significant delays.

More from our Archive