TD-RA policy-enforcement framework for an SDN-based IoT architecture

被引:4
|
作者
Lahlou, Sara [1 ]
Moukafih, Youness [1 ,2 ]
Sebbar, Anass [1 ]
Zkik, Karim [3 ]
Boulmalf, Mohammed [1 ]
Ghogho, Mounir [1 ]
机构
[1] Int Univ Rabat, TICLab, Rabat, Morocco
[2] Univ Lorraine, LORIA INRIA Lorraine, Lorraine, France
[3] ESAIP Grad Sch Engn, Angers, France
关键词
SDN-based IoT; Security; Machine learning; Threat detection; Policy enforcement; SOFTWARE-DEFINED NETWORKS; ATTACK; SECURITY; INTERNET;
D O I
10.1016/j.jnca.2022.103390
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Internet of Things (IoT) has been suffering from increasing security threats since many years which compromise the whole network security. Automating the management of IoT devices helps in implementing security measures within communication systems. Software Defined Networking (SDN) has been introduced as a new networking approach that enables this automation. Many approaches were developed to mitigate IoT attacks in SDN-based IoT networks. Some studies investigated the prevention of flooding attacks, while others tried to cover broader attack surfaces. However, their proposed methods are time consuming and resource-exhausting as they use complex algorithms. In this paper, we propose a lightweight secure Threat Detection (TD) and Rule Automation (RA) framework namely "TD-RA'' to effectively detect and mitigate different cyber-security threats in an SDN-based IoT environment. The proposed solution is composed of a Binary and Multi-class Classification Modules (BCM/MCM) for IoT threat detection and a Policy-Enforcement Module (PEM) for attack mitigation. Different machine learning methods have been implemented and compared to solve the classification problems. It is shown that for binary classification, the Decision Tree method achieves the highest accuracy which is around 98.7%, while for multi-class classification, Random Forest achieves the highest accuracy which is around 91.1%. The experimental results show that the proposed framework can successfully detect abnormal traffic and prevent IoT threats through SDN with smaller network overhead and high performance. Moreover, the overall processing time of our security modules is significantly smaller than that of existing solutions by reaching a mean value of 6 ms. This paper also introduces a large-scale architecture that comprises clusters of controllers to maintain high availability of network services. Such an integrated security approach, including detection and mitigation techniques, provides IT industries with reliable security measures that can be implemented to increase SDN-based IoT system responsiveness to different IoT attacks.
引用
收藏
页数:20
相关论文
共 50 条
  • [21] Towards a standard SDN-based IPsec management framework
    Lopez-Millan, Gabriel
    Marin-Lopez, Rafael
    Pereniguez-Garcia, Fernando
    COMPUTER STANDARDS & INTERFACES, 2019, 66
  • [22] A Novel Framework for Misbehavior Detection in SDN-based VANET
    Sultana, Rukhsar
    Grover, Jyoti
    Tripathi, Meenakshi
    2020 IEEE INTERNATIONAL CONFERENCE ON ADVANCED NETWORKS AND TELECOMMUNICATIONS SYSTEMS (IEEE ANTS), 2020,
  • [23] μSDN: An SDN-based Routing Architecture for Wireless Sensor Networks
    da Silva Santos, Leonardo Francisco
    de Mendonca Junior, Francisco Ferreira
    Dias, Kelvin Lopes
    2017 VII BRAZILIAN SYMPOSIUM ON COMPUTING SYSTEMS ENGINEERING (SBESC), 2017, : 63 - 70
  • [24] SDN based architecture for IoT and improvement of the security
    Flauzac, Olivier
    Gonzalez, Carlos
    Hachani, Abdelhak
    Nolot, Florent
    2015 IEEE 29TH INTERNATIONAL CONFERENCE ON ADVANCED INFORMATION NETWORKING AND APPLICATIONS WORKSHOPS WAINA 2015, 2015, : 688 - 693
  • [25] SDMob: SDN-Based Mobility Management for IoT Networks
    Rabet, Iliar
    Selvaraju, Shunmuga Priyan
    Fotouhi, Hossein
    Alves, Mario
    Vahabi, Maryam
    Balador, Ali
    Bjorkman, Mats
    JOURNAL OF SENSOR AND ACTUATOR NETWORKS, 2022, 11 (01)
  • [26] A SDN-based network architecture for cloud resiliency
    Fressancourt, Antoine
    Gagnaire, Maurice
    2015 12TH ANNUAL IEEE CONSUMER COMMUNICATIONS AND NETWORKING CONFERENCE, 2015, : 479 - 484
  • [27] Policy-based Bigdata Security and QoS Framework for SDN/IoT: An Analytic Approach
    Pokhrel, Shiva Raj
    Sood, Keshav
    Yu, Shui
    Nosouhi, Mohammad Reza
    IEEE CONFERENCE ON COMPUTER COMMUNICATIONS WORKSHOPS (IEEE INFOCOM 2019 WKSHPS), 2019, : 73 - 78
  • [28] An Energy-Efficient SDN Controller Architecture for IoT Networks With Blockchain-Based Security
    Yazdinejad, Abbas
    Parizi, Reza M.
    Dehghantanha, Ali
    Zhang, Qi
    Choo, Kim-Kwang Raymond
    IEEE TRANSACTIONS ON SERVICES COMPUTING, 2020, 13 (04) : 625 - 638
  • [29] An efficient architecture for dynamic middlebox policy enforcement in SDN networks
    Pinheiro, Antonio J.
    Gondim, Ethel B.
    Campelo, Divanilson R.
    COMPUTER NETWORKS, 2017, 122 : 153 - 162
  • [30] A Multiprotocol Controller Deployment in SDN-Based IoMT Architecture
    Cicioglu, Murtaza
    Calhan, Ali
    IEEE INTERNET OF THINGS JOURNAL, 2022, 9 (21) : 20833 - 20840