A Security Enforcement Framework for SDN Controller Using Game Theoretic Approach

被引:8
作者
Priyadarsini, Madhukrishna [1 ]
Bera, Padmalochan [2 ]
Das, Sajal K. [3 ]
Rahman, Mohammad Ashiqur [4 ]
机构
[1] KIIT Deemed Univ, Bhubaneswar 751024, India
[2] Indian Inst Technol, Bhubaneswar 752050, India
[3] Missouri Univ Sci & Technol, Rolla, MO 65409 USA
[4] Florida Int Univ, Miami, FL 33199 USA
基金
俄罗斯基础研究基金会;
关键词
SDN; security; trust model; risk verification; attack model; vulnerability analysis; INTERNET;
D O I
10.1109/TDSC.2022.3158690
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Software-defined networking (SDN) has gained significant attention as the future deployment platform for the Internet and enterprise networks. The major advantages of SDN include effective traffic management, dynamic configuration of policy and flow rules, and better scalability with heterogeneous traffic requirements. However, centralized network control and the use of OpenFlow protocols introduce various security challenges for the underlying network. The attacks on the SDN controller is critical as it hosts all network control functions. Motivated by a systematic analysis of different attack scenarios in SDN using the STRIDE attack model, this article presents an effective security enforcement framework for proactive prevention of potential attacks on SDN controllers. First, based on a signaling game approach, we design a trust-based controller attack detection (TCAD) model that calculates the trust value of each incoming packet to take necessary action. Next, we propose a risk-based attack prevention (RAP) model that detects and filters malicious traffic flows in the network. Finally, we evaluate our proposed security enforcement framework on different scenarios with varying traffic requirements and by injecting attacks based on the STRIDE model. Experimental results show 95% accuracy in the potential attack detection and prevention.
引用
收藏
页码:1500 / 1515
页数:16
相关论文
共 50 条
  • [1] A Signalling Game-Based Security Enforcement Mechanism for SDN Controllers
    Priyadarsini, Madhukrishna
    Bera, Padmalochan
    Rahman, M. Ashiqur
    2019 10TH INTERNATIONAL CONFERENCE ON COMPUTING, COMMUNICATION AND NETWORKING TECHNOLOGIES (ICCCNT), 2019,
  • [2] Security network policy enforcement through a SDN framework
    Berardi, Davide
    Callegati, Franco
    Melis, Andrea
    Prandini, Marco
    2018 28TH INTERNATIONAL TELECOMMUNICATION NETWORKS AND APPLICATIONS CONFERENCE (ITNAC), 2018, : 97 - 100
  • [3] SDN-Based Security Enforcement Framework for Data Sharing Systems of Smart Healthcare
    Meng, Yunfei
    Huang, Zhiqiu
    Shen, Guohua
    Ke, Changbo
    IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2020, 17 (01): : 308 - 318
  • [4] Security in Networks: A Game-Theoretic Approach
    Gueye, Assane
    Walrand, Jean C.
    47TH IEEE CONFERENCE ON DECISION AND CONTROL, 2008 (CDC 2008), 2008, : 829 - 834
  • [5] Game Theoretic Security Framework for Quantum Key Distribution
    Krawec, Walter O.
    Miao, Fei
    DECISION AND GAME THEORY FOR SECURITY, GAMESEC 2018, 2018, 11199 : 38 - 58
  • [6] Game-Theoretic Framework for Malicious Controller Detection in Software Defined Networks
    Sridharan, Vignesh
    Gurusamy, Mohan
    IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2021, 18 (03): : 3107 - 3120
  • [7] An Efficient Approach to Robust SDN Controller Placement for Security
    Yang, Shu
    Cui, Laizhong
    Chen, Ziteng
    Xiao, Wei
    IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2020, 17 (03): : 1669 - 1682
  • [8] Proof-of-Balance: Game-Theoretic Consensus for Controller Load Balancing of SDN
    Liao, Siyi
    Wu, Jun
    Li, Jianhua
    Bashir, Ali Kashif
    IEEE INFOCOM 2020 - IEEE CONFERENCE ON COMPUTER COMMUNICATIONS WORKSHOPS (INFOCOM WKSHPS), 2020, : 231 - 236
  • [9] Security of Vehicle Platooning: A Game-Theoretic Approach
    Basiri, Mohammad Hossein
    Pirani, Mohammad
    Azad, Nasser L.
    Fischmeister, Sebastian
    IEEE ACCESS, 2019, 7 : 185565 - 185579
  • [10] A Game-Theoretic Approach for Enhancing Security and Data Trustworthiness in IoT Applications
    Abdalzaher, Mohamed S.
    Muta, Osamu
    IEEE INTERNET OF THINGS JOURNAL, 2020, 7 (11): : 11250 - 11261