Secure SDN-IoT Framework for DDoS Attack Detection Using Deep Learning and Counter Based Approach

被引:18
作者
Cherian, Mimi [1 ]
Varma, Satishkumar L. [1 ]
机构
[1] Mumbai Univ, Pillai Coll Engn, Comp Engn, Navi Mumbai, India
关键词
DDoS attack and Detection; IoT security; Software-defined network; Deep learning; ANOMALY DETECTION; MITIGATION; MACHINE;
D O I
10.1007/s10922-023-09749-w
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The IoT network is unique due to heterogeneous IoT nodes and resource-constrained devices; the approach for securing IoT networks needs to be different from the security measures implemented for traditional network communication. In IoT networks, various security vulnerabilities are exploited by an attacker to generate a variety of DDoS attacks. In this paper, the authors propose a unique approach for securing IoT networks using an SDN-enabled framework that incorporates a dynamic counter-based approach and deep learning models. The aim is to detect and mitigate various security vulnerabilities that attackers exploit to generate DDoS attacks in IoT networks. Specifically, the proposed framework is tested using the CICDDoS2019 dataset to identify reflection attacks and exploitation attacks in TCP, UDP, and ICMP. The framework is also analyzed by varying network parameters such as the number of IoT attack nodes and payload to measure the performance of the SDN controller workload, CPU utilization, and attack detection time. The experimental results demonstrate that the proposed framework can efficiently detect and mitigate DDoS attacks while utilizing CPU resources effectively and in a shorter time compared to existing approaches.
引用
收藏
页数:48
相关论文
共 49 条
[1]   Novel Anonymous Key Establishment Protocol for Isolated Smart Meters [J].
Abbasinezhad-Mood, Dariush ;
Ostad-Sharif, Arezou ;
Nikooghadam, Morteza .
IEEE TRANSACTIONS ON INDUSTRIAL ELECTRONICS, 2020, 67 (04) :2844-2851
[2]   Efficient Design of a Novel ECC-Based Public Key Scheme for Medical Data Protection by Utilization of NanoPi Fire [J].
Abbasinezhad-Mood, Dariush ;
Nikooghadam, Morteza .
IEEE TRANSACTIONS ON RELIABILITY, 2018, 67 (03) :1328-1339
[3]   An Anonymous ECC-Based Self-Certified Key Distribution Scheme for the Smart Grid [J].
Abbasinezhad-Mood, Dariush ;
Nikooghadam, Morteza .
IEEE TRANSACTIONS ON INDUSTRIAL ELECTRONICS, 2018, 65 (10) :7996-8004
[4]   A hybrid entropy-based DoS attacks detection system for software defined networks (SDN): A proposed trust mechanism [J].
AbdelAzim, Nada M. ;
Fahmy, Sherif F. ;
Sobh, Mohammed Ali ;
Eldin, Ayman M. Bahaa .
EGYPTIAN INFORMATICS JOURNAL, 2021, 22 (01) :85-90
[5]   State-of-the-art survey of artificial intelligent techniques for IoT security [J].
Ahanger, Tariq Ahamed ;
Aljumah, Abdullah ;
Atiquzzaman, Mohammed .
COMPUTER NETWORKS, 2022, 206
[6]   Performance Analysis of POX and Ryu with Different SDN Topologies [J].
Ali, Jehad ;
Lee, Seungwoon ;
Roh, Byeong-hee .
PROCEEDINGS OF THE 2018 INTERNATIONAL CONFERENCE ON INFORMATION SCIENCE AND SYSTEM (ICISS 2018), 2018, :244-249
[7]   An Efficient Counter-Based DDoS Attack Detection Framework Leveraging Software Defined IoT (SD-IoT) [J].
Bhayo, Jalal ;
Hameed, Sufian ;
Shah, Syed Attique .
IEEE ACCESS, 2020, 8 :221612-221631
[8]   Investigation of the problem of classifying unbalanced datasets in identifying distributed denial of service attacks [J].
Bolodurina, I ;
Shukhman, A. ;
Parfenov, D. ;
Zhigalov, A. ;
Zabrodina, L. .
II INTERNATIONAL SCIENTIFIC CONFERENCE ON APPLIED PHYSICS, INFORMATION TECHNOLOGIES AND ENGINEERING 25, PTS 1-5, 2020, 1679
[9]   Dynamic clustering of software defined network switches and controller placement using deep reinforcement learning [J].
Bouzidi, El Hocine ;
Outtagarts, Abdelkader ;
Langar, Rami ;
Boutaba, Raouf .
COMPUTER NETWORKS, 2022, 207
[10]   Flow Based Security for IoT Devices using an SDN Gateway [J].
Bull, Peter ;
Austin, Ron ;
Popov, Evgenii ;
Sharma, Mak ;
Watson, Richard .
2016 IEEE 4TH INTERNATIONAL CONFERENCE ON FUTURE INTERNET OF THINGS AND CLOUD (FICLOUD 2016), 2016, :159-165