A Security Enforcement Framework for SDN Controller Using Game Theoretic Approach

被引:9
作者
Priyadarsini, Madhukrishna [1 ]
Bera, Padmalochan [2 ]
Das, Sajal K. [3 ]
Rahman, Mohammad Ashiqur [4 ]
机构
[1] KIIT Deemed Univ, Bhubaneswar 751024, India
[2] Indian Inst Technol, Bhubaneswar 752050, India
[3] Missouri Univ Sci & Technol, Rolla, MO 65409 USA
[4] Florida Int Univ, Miami, FL 33199 USA
基金
俄罗斯基础研究基金会;
关键词
SDN; security; trust model; risk verification; attack model; vulnerability analysis; INTERNET;
D O I
10.1109/TDSC.2022.3158690
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Software-defined networking (SDN) has gained significant attention as the future deployment platform for the Internet and enterprise networks. The major advantages of SDN include effective traffic management, dynamic configuration of policy and flow rules, and better scalability with heterogeneous traffic requirements. However, centralized network control and the use of OpenFlow protocols introduce various security challenges for the underlying network. The attacks on the SDN controller is critical as it hosts all network control functions. Motivated by a systematic analysis of different attack scenarios in SDN using the STRIDE attack model, this article presents an effective security enforcement framework for proactive prevention of potential attacks on SDN controllers. First, based on a signaling game approach, we design a trust-based controller attack detection (TCAD) model that calculates the trust value of each incoming packet to take necessary action. Next, we propose a risk-based attack prevention (RAP) model that detects and filters malicious traffic flows in the network. Finally, we evaluate our proposed security enforcement framework on different scenarios with varying traffic requirements and by injecting attacks based on the STRIDE model. Experimental results show 95% accuracy in the potential attack detection and prevention.
引用
收藏
页码:1500 / 1515
页数:16
相关论文
共 50 条
[21]   Automatic, verifiable and optimized policy-based security enforcement for SDN-aware IoT networks [J].
Bringhenti, Daniele ;
Yusupov, Jalolliddin ;
Zarca, Alejandro Molina ;
Valenza, Fulvio ;
Sisto, Riccardo ;
Bernabe, Jorge Bernal ;
Skarmeta, Antonio .
COMPUTER NETWORKS, 2022, 213
[22]   DEFENSIVE MECHANISM FOR VANET SECURITY IN GAME THEORETIC APPROACH USING HEURISTIC BASED ANT COLONY OPTIMIZATION [J].
Prabhakar, M. ;
Singh, J. N. ;
Mahadevan, G. .
2013 INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATION AND INFORMATICS, 2013,
[23]   A Game-Theoretic Approach for Enhancing Data Privacy in SDN-Based Smart Grids [J].
Sivaraman, Vignesh ;
Sikdar, Biplab .
IEEE INTERNET OF THINGS JOURNAL, 2021, 8 (13) :10583-10595
[24]   A Framework for Security Enhancement in SDN-based Datacenters [J].
Ammar, Moustafa ;
Rizk, Mohamed ;
Abdel-Hamid, Ayman ;
Aboul-Seoud, Ahmed K. .
2016 8TH IFIP INTERNATIONAL CONFERENCE ON NEW TECHNOLOGIES, MOBILITY AND SECURITY (NTMS), 2016,
[25]   CyberShip-IoT: A dynamic and adaptive SDN-based security policy enforcement framework for ships [J].
Sahay, Rishikesh ;
Meng, Weizhi ;
Estay, D. A. Sepulveda ;
Jensen, Christian D. ;
Barfod, Michael Bruhn .
FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2019, 100 :736-750
[26]   On the Security of SDN: A Completed Secure and Scalable Framework Using the Software-Defined Perimeter [J].
Sallam, Ahmed ;
Refaey, Ahmed ;
Shami, Abdallah .
IEEE ACCESS, 2019, 7 :146577-146587
[27]   Dynamic Controller Deployment in SDN Networks Using ML Approach [J].
Thiruvengadam, Hemamalini ;
Gopalakrishnan, Ramya ;
Rajendiran, Manoharan .
SUSTAINABLE COMMUNICATION NETWORKS AND APPLICATION, ICSCN 2019, 2020, 39 :311-318
[28]   A Game Theoretic Approach for Quantitative Evaluation of Security by Considering Hackers with Diverse Behaviors [J].
Moayedi, Behzad Zare ;
Azgomi, Mohammad Abdollahi .
EIGHTH IEEE INTERNATIONAL CONFERENCE ON DEPENDABLE, AUTONOMIC AND SECURE COMPUTING, PROCEEDINGS, 2009, :508-513
[29]   An Energy-Efficient SDN Controller Architecture for IoT Networks With Blockchain-Based Security [J].
Yazdinejad, Abbas ;
Parizi, Reza M. ;
Dehghantanha, Ali ;
Zhang, Qi ;
Choo, Kim-Kwang Raymond .
IEEE TRANSACTIONS ON SERVICES COMPUTING, 2020, 13 (04) :625-638
[30]   Novel framework for enhancing security of SDN based VPLS architecture [J].
Gaur, Kuntal ;
Rawat, Umashankar ;
Acharya, Saket ;
Kumar, Pradeep ;
Kalla, Anshuman .
JOURNAL OF DISCRETE MATHEMATICAL SCIENCES & CRYPTOGRAPHY, 2024, 27 (04) :1331-1343