TD-RA policy-enforcement framework for an SDN-based IoT architecture

被引:4
|
作者
Lahlou, Sara [1 ]
Moukafih, Youness [1 ,2 ]
Sebbar, Anass [1 ]
Zkik, Karim [3 ]
Boulmalf, Mohammed [1 ]
Ghogho, Mounir [1 ]
机构
[1] Int Univ Rabat, TICLab, Rabat, Morocco
[2] Univ Lorraine, LORIA INRIA Lorraine, Lorraine, France
[3] ESAIP Grad Sch Engn, Angers, France
关键词
SDN-based IoT; Security; Machine learning; Threat detection; Policy enforcement; SOFTWARE-DEFINED NETWORKS; ATTACK; SECURITY; INTERNET;
D O I
10.1016/j.jnca.2022.103390
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Internet of Things (IoT) has been suffering from increasing security threats since many years which compromise the whole network security. Automating the management of IoT devices helps in implementing security measures within communication systems. Software Defined Networking (SDN) has been introduced as a new networking approach that enables this automation. Many approaches were developed to mitigate IoT attacks in SDN-based IoT networks. Some studies investigated the prevention of flooding attacks, while others tried to cover broader attack surfaces. However, their proposed methods are time consuming and resource-exhausting as they use complex algorithms. In this paper, we propose a lightweight secure Threat Detection (TD) and Rule Automation (RA) framework namely "TD-RA'' to effectively detect and mitigate different cyber-security threats in an SDN-based IoT environment. The proposed solution is composed of a Binary and Multi-class Classification Modules (BCM/MCM) for IoT threat detection and a Policy-Enforcement Module (PEM) for attack mitigation. Different machine learning methods have been implemented and compared to solve the classification problems. It is shown that for binary classification, the Decision Tree method achieves the highest accuracy which is around 98.7%, while for multi-class classification, Random Forest achieves the highest accuracy which is around 91.1%. The experimental results show that the proposed framework can successfully detect abnormal traffic and prevent IoT threats through SDN with smaller network overhead and high performance. Moreover, the overall processing time of our security modules is significantly smaller than that of existing solutions by reaching a mean value of 6 ms. This paper also introduces a large-scale architecture that comprises clusters of controllers to maintain high availability of network services. Such an integrated security approach, including detection and mitigation techniques, provides IT industries with reliable security measures that can be implemented to increase SDN-based IoT system responsiveness to different IoT attacks.
引用
收藏
页数:20
相关论文
共 50 条
  • [31] Mitigating DDoS Attacks in SDN-Based IoT Networks Leveraging Secure Control and Data Plane Algorithm
    Wang, Song
    Gomez, Karina
    Sithamparanathan, Kandeepan
    Asghar, Muhammad Rizwan
    Russello, Giovanni
    Zanna, Paul
    APPLIED SCIENCES-BASEL, 2021, 11 (03): : 1 - 27
  • [32] An IoT Framework Based on SDN and NFV for Context-Aware Security
    Ong, Arlyn Verina
    Peradilla, Marnel
    12TH INTERNATIONAL CONFERENCE ON UBIQUITOUS AND FUTURE NETWORKS (ICUFN 2021), 2021, : 167 - 172
  • [33] SDN-based gateway architecture for electromagnetic nano-networks
    Galal, Akram
    Hesselbach, Xavier
    Tavernier, Wouter
    Colle, Didier
    COMPUTER COMMUNICATIONS, 2022, 184 : 160 - 173
  • [34] SDN-based dynamic resource management and scheduling for cognitive industrial IoT
    Chandramohan, S.
    Senthilkumaran, M.
    INTERNATIONAL JOURNAL OF INTELLIGENT COMPUTING AND CYBERNETICS, 2022, 15 (03) : 425 - 437
  • [35] Caching Popular Transient IoT Contents in an SDN-Based Edge Infrastructure
    Ruggeri, Giuseppe
    Amadeo, Marica
    Campolo, Claudia
    Molinaro, Antonella
    Iera, Antonio
    IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2021, 18 (03): : 3432 - 3447
  • [36] A new SDN-based framework for wireless local area networks
    Jalili, Ahmad
    INTERNATIONAL JOURNAL OF NONLINEAR ANALYSIS AND APPLICATIONS, 2019, 10 (01): : 177 - 183
  • [37] SDN-Based Application Framework for Wireless Sensor and Actor Networks
    Zhou, Jianguo
    Jiang, Hao
    Wu, Jing
    Wu, Lihua
    Zhu, Chunsheng
    Li, Wenxiang
    IEEE ACCESS, 2016, 4 : 1583 - 1594
  • [38] An IoT-based packet aggregation mechanism for the SDN-based wide area networks
    Kazemi, Nader
    Ghaderi, Reza
    Nazari, Soheila
    COMPUTER NETWORKS, 2024, 248
  • [39] A distributed SDN-based intrusion detection system for IoT using optimized forests
    Luo, Ke
    PLOS ONE, 2023, 18 (08):
  • [40] Towards a SDN-Based Integrated Architecture for Mitigating IP Spoofing Attack
    Zhang, Chaoqin
    Hu, Guangwu
    Chen, Guolong
    Sangaiah, Arun Kumar
    Zhang, Ping'an
    Yan, Xia
    Jiang, Weijin
    IEEE ACCESS, 2018, 6 : 22764 - 22777