A Security Enforcement Framework for SDN Controller Using Game Theoretic Approach

被引:9
作者
Priyadarsini, Madhukrishna [1 ]
Bera, Padmalochan [2 ]
Das, Sajal K. [3 ]
Rahman, Mohammad Ashiqur [4 ]
机构
[1] KIIT Deemed Univ, Bhubaneswar 751024, India
[2] Indian Inst Technol, Bhubaneswar 752050, India
[3] Missouri Univ Sci & Technol, Rolla, MO 65409 USA
[4] Florida Int Univ, Miami, FL 33199 USA
基金
俄罗斯基础研究基金会;
关键词
SDN; security; trust model; risk verification; attack model; vulnerability analysis; INTERNET;
D O I
10.1109/TDSC.2022.3158690
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Software-defined networking (SDN) has gained significant attention as the future deployment platform for the Internet and enterprise networks. The major advantages of SDN include effective traffic management, dynamic configuration of policy and flow rules, and better scalability with heterogeneous traffic requirements. However, centralized network control and the use of OpenFlow protocols introduce various security challenges for the underlying network. The attacks on the SDN controller is critical as it hosts all network control functions. Motivated by a systematic analysis of different attack scenarios in SDN using the STRIDE attack model, this article presents an effective security enforcement framework for proactive prevention of potential attacks on SDN controllers. First, based on a signaling game approach, we design a trust-based controller attack detection (TCAD) model that calculates the trust value of each incoming packet to take necessary action. Next, we propose a risk-based attack prevention (RAP) model that detects and filters malicious traffic flows in the network. Finally, we evaluate our proposed security enforcement framework on different scenarios with varying traffic requirements and by injecting attacks based on the STRIDE model. Experimental results show 95% accuracy in the potential attack detection and prevention.
引用
收藏
页码:1500 / 1515
页数:16
相关论文
共 50 条
[41]   Security analysis of SDN controller-based DHCP services and attack mitigation with DHCPguard [J].
Tok, Mevlut Serkan ;
Demirci, Mehmet .
COMPUTERS & SECURITY, 2021, 109
[42]   Game-Theoretic Security Analysis in Heterogeneous IoT Networks: A Competition Perspective [J].
Zhu, Yuyao ;
Wu, Huici ;
Tao, Xiaofeng ;
Wang, Shen .
IEEE INTERNET OF THINGS JOURNAL, 2024, 11 (21) :35048-35059
[43]   An Information Theoretic Framework for Biometric Security Systems [J].
Lai, Lifeng ;
Ho, Siu-Wai ;
Poor, H. Vincent .
ADVANCES IN BIOMETRICS, 2009, 5558 :879-+
[44]   TD-RA policy-enforcement framework for an SDN-based IoT architecture [J].
Lahlou, Sara ;
Moukafih, Youness ;
Sebbar, Anass ;
Zkik, Karim ;
Boulmalf, Mohammed ;
Ghogho, Mounir .
JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2022, 204
[45]   TENNISON: A Distributed SDN Framework for Scalable Network Security [J].
Fawcett, Lyndon ;
Scott-Hayward, Sandra ;
Broadbent, Matthew ;
Wright, Andrew ;
Race, Nicholas .
IEEE JOURNAL ON SELECTED AREAS IN COMMUNICATIONS, 2018, 36 (12) :2805-2818
[46]   A Game Theoretic Approach for Security and Quality of Service (QoS) Co-Design in MANETs with Cooperative Communications [J].
Zheng, Du ;
Tang, Helen ;
Yu, F. Richard .
2012 IEEE MILITARY COMMUNICATIONS CONFERENCE (MILCOM 2012), 2012,
[47]   Contested Logistics: A Game-Theoretic Approach [J].
Cerny, Jakub ;
Ling, Chun Kai ;
Chakrabarti, Darshan ;
Zhang, Jingwen ;
Farina, Gabriele ;
Kroer, Christian ;
Iyengar, Garud .
DECISION AND GAME THEORY FOR SECURITY, GAMESEC 2024, 2025, 14908 :124-146
[48]   Controller Placement Approach with Criteria Balance in SDN networks [J].
Fellah, Soumaya ;
Fellah, Khadidja .
JOURNAL OF HIGH SPEED NETWORKS, 2024, 30 (04) :497-516
[49]   Dynamic security management of smart WoT infrastructures using SDN [J].
El Jaouhari, Saad ;
Bouabdallah, Ahmed .
2018 IEEE 88TH VEHICULAR TECHNOLOGY CONFERENCE (VTC-FALL), 2018,
[50]   SDN-Based Security Framework for the IoT in Distributed Grid [J].
Gonzalez, Carlos ;
Charfadine, Salim Mahamat ;
Flauzac, Olivier ;
Nolot, Florent .
2016 INTERNATIONAL MULTIDISCIPLINARY CONFERENCE ON COMPUTER AND ENERGY SCIENCE (SPLITECH), 2016, :81-85