A Security Enforcement Framework for SDN Controller Using Game Theoretic Approach

被引:9
作者
Priyadarsini, Madhukrishna [1 ]
Bera, Padmalochan [2 ]
Das, Sajal K. [3 ]
Rahman, Mohammad Ashiqur [4 ]
机构
[1] KIIT Deemed Univ, Bhubaneswar 751024, India
[2] Indian Inst Technol, Bhubaneswar 752050, India
[3] Missouri Univ Sci & Technol, Rolla, MO 65409 USA
[4] Florida Int Univ, Miami, FL 33199 USA
基金
俄罗斯基础研究基金会;
关键词
SDN; security; trust model; risk verification; attack model; vulnerability analysis; INTERNET;
D O I
10.1109/TDSC.2022.3158690
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Software-defined networking (SDN) has gained significant attention as the future deployment platform for the Internet and enterprise networks. The major advantages of SDN include effective traffic management, dynamic configuration of policy and flow rules, and better scalability with heterogeneous traffic requirements. However, centralized network control and the use of OpenFlow protocols introduce various security challenges for the underlying network. The attacks on the SDN controller is critical as it hosts all network control functions. Motivated by a systematic analysis of different attack scenarios in SDN using the STRIDE attack model, this article presents an effective security enforcement framework for proactive prevention of potential attacks on SDN controllers. First, based on a signaling game approach, we design a trust-based controller attack detection (TCAD) model that calculates the trust value of each incoming packet to take necessary action. Next, we propose a risk-based attack prevention (RAP) model that detects and filters malicious traffic flows in the network. Finally, we evaluate our proposed security enforcement framework on different scenarios with varying traffic requirements and by injecting attacks based on the STRIDE model. Experimental results show 95% accuracy in the potential attack detection and prevention.
引用
收藏
页码:1500 / 1515
页数:16
相关论文
共 50 条
[31]   A Security Framework for SDN-enabled Smart Power Grids [J].
Ghosh, Uttam ;
Chatterjee, Pushpita ;
Shetty, Sachin .
2017 IEEE 37TH INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING SYSTEMS WORKSHOPS (ICDCSW), 2017, :113-118
[32]   Mean field game theoretic approach for security in mobile ad-hoc networks [J].
Wang, Yanwei ;
Tang, Helen ;
Yu, F. Richard ;
Huang, Minyi .
MOBILE MULTIMEDIA/IMAGE PROCESSING, SECURITY, AND APPLICATIONS 2013, 2013, 8755
[33]   A Mean Field Game Theoretic Approach for Security Enhancements in Mobile Ad hoc Networks [J].
Wang, Yanwei ;
Yu, F. Richard ;
Tang, Helen ;
Huang, Minyi .
IEEE TRANSACTIONS ON WIRELESS COMMUNICATIONS, 2014, 13 (03) :1616-1627
[34]   CROCUS: An Objective Approach for SDN Controllers Security Assessment [J].
Silva, Carlos ;
Sousa, Bruno ;
Vilela, Joao P. .
SECURITY AND PRIVACY IN COMMUNICATION NETWORKS, SECURECOMM 2021, PT I, 2021, 398 :438-455
[35]   A Novel Software Defined Security Framework for SDN [J].
Basu, Srijita ;
Raun, Neha Firdaush ;
Ghosal, Avishek ;
Chatterjee, Debanjan ;
Maitra, Debarghya ;
Mazumdar, Chandan .
RISKS AND SECURITY OF INTERNET AND SYSTEMS, CRISIS 2023, 2023, 14529 :216-230
[36]   Security Orchestration and Enforcement in NFV/SDN-Aware UAV Deployments [J].
Hermosilla, Ana ;
Molina Zarca, Alejandro ;
Bernal Bernabe, Jorge ;
Ortiz, Jordi ;
Skarmeta, Antonio .
IEEE ACCESS, 2020, 8 :131779-131795
[37]   Policy-based Bigdata Security and QoS Framework for SDN/IoT: An Analytic Approach [J].
Pokhrel, Shiva Raj ;
Sood, Keshav ;
Yu, Shui ;
Nosouhi, Mohammad Reza .
IEEE CONFERENCE ON COMPUTER COMMUNICATIONS WORKSHOPS (IEEE INFOCOM 2019 WKSHPS), 2019, :73-78
[38]   Game theoretic modeling of security and trust relationship in cyberspace [J].
Njilla, Laurent Yamen ;
Pissinou, Niki ;
Makki, Kia .
INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2016, 29 (09) :1500-1512
[39]   Automated Game-Theoretic Verification of Security Systems [J].
Mu, Chunyan .
QUANTITATIVE EVALUATION OF SYSTEMS (QEST 2019), 2019, 11785 :239-256
[40]   A trust management framework for Software Defined Network (SDN) controller and network applications [J].
Aliyu, Aliyu Lawal ;
Aneiba, Adel ;
Patwary, Mohammad ;
Bull, Peter .
COMPUTER NETWORKS, 2020, 181