TD-RA policy-enforcement framework for an SDN-based IoT architecture

被引:4
|
作者
Lahlou, Sara [1 ]
Moukafih, Youness [1 ,2 ]
Sebbar, Anass [1 ]
Zkik, Karim [3 ]
Boulmalf, Mohammed [1 ]
Ghogho, Mounir [1 ]
机构
[1] Int Univ Rabat, TICLab, Rabat, Morocco
[2] Univ Lorraine, LORIA INRIA Lorraine, Lorraine, France
[3] ESAIP Grad Sch Engn, Angers, France
关键词
SDN-based IoT; Security; Machine learning; Threat detection; Policy enforcement; SOFTWARE-DEFINED NETWORKS; ATTACK; SECURITY; INTERNET;
D O I
10.1016/j.jnca.2022.103390
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Internet of Things (IoT) has been suffering from increasing security threats since many years which compromise the whole network security. Automating the management of IoT devices helps in implementing security measures within communication systems. Software Defined Networking (SDN) has been introduced as a new networking approach that enables this automation. Many approaches were developed to mitigate IoT attacks in SDN-based IoT networks. Some studies investigated the prevention of flooding attacks, while others tried to cover broader attack surfaces. However, their proposed methods are time consuming and resource-exhausting as they use complex algorithms. In this paper, we propose a lightweight secure Threat Detection (TD) and Rule Automation (RA) framework namely "TD-RA'' to effectively detect and mitigate different cyber-security threats in an SDN-based IoT environment. The proposed solution is composed of a Binary and Multi-class Classification Modules (BCM/MCM) for IoT threat detection and a Policy-Enforcement Module (PEM) for attack mitigation. Different machine learning methods have been implemented and compared to solve the classification problems. It is shown that for binary classification, the Decision Tree method achieves the highest accuracy which is around 98.7%, while for multi-class classification, Random Forest achieves the highest accuracy which is around 91.1%. The experimental results show that the proposed framework can successfully detect abnormal traffic and prevent IoT threats through SDN with smaller network overhead and high performance. Moreover, the overall processing time of our security modules is significantly smaller than that of existing solutions by reaching a mean value of 6 ms. This paper also introduces a large-scale architecture that comprises clusters of controllers to maintain high availability of network services. Such an integrated security approach, including detection and mitigation techniques, provides IT industries with reliable security measures that can be implemented to increase SDN-based IoT system responsiveness to different IoT attacks.
引用
收藏
页数:20
相关论文
共 50 条
  • [41] SDN-Based Federated Learning Approach for Satellite-IoT Framework to Enhance Data Security and Privacy in Space Communication
    Uddin, Ryhan
    Kumar, Sathish A. P.
    IEEE JOURNAL OF RADIO FREQUENCY IDENTIFICATION, 2023, 7 : 424 - 440
  • [42] SDN-based Federated Learning approach for Satellite-IoT Framework to Enhance Data Security and Privacy in Space Communication
    Uddin, Ryhan
    Kumar, Sathish
    2022 IEEE INTERNATIONAL CONFERENCE ON WIRELESS FOR SPACE AND EXTREME ENVIRONMENTS (WISEE 2022), 2022, : 71 - 76
  • [43] SDN-based Predictive Alarm Manager for Security Attacks Detection at the IoT Gateways
    Thorat, Pankaj
    Dubey, Niraj Kumar
    Khetan, Kunal
    Challa, Rajesh
    2021 IEEE 18TH ANNUAL CONSUMER COMMUNICATIONS & NETWORKING CONFERENCE (CCNC), 2021,
  • [44] Towards a blockchain-SDN-based secure architecture for cloud computing in smart industrial IoT
    Rahman, Anichur
    Islam, Md Jahidul
    Band, Shahab S.
    Muhammad, Ghulam
    Hasan, Kamrul
    Tiwari, Prayag
    DIGITAL COMMUNICATIONS AND NETWORKS, 2023, 9 (02) : 411 - 421
  • [45] Optimal IoT Service Offloading with Uncertainty in SDN-Based Mobile Edge Computing
    Hao, Huizhen
    Zhang, Jie
    Gu, Qing
    MOBILE NETWORKS & APPLICATIONS, 2022, 27 (06) : 2318 - 2327
  • [46] SDN-based multi-level framework for smart home services
    Gilani, Syed Mushhad Mustuzhar
    Usman, Muhammad
    Daud, Saqib
    Kabir, Asif
    Nawaz, Qamar
    Judit, Olah
    MULTIMEDIA TOOLS AND APPLICATIONS, 2023, 83 (1) : 327 - 347
  • [47] SDN-DMQTT: SDN-Based Platform for Re-configurable MQTT Distributed Brokers Architecture
    Hmissi, Fatma
    Ouni, Sofiane
    MOBILE AND UBIQUITOUS SYSTEMS: COMPUTING, NETWORKING AND SERVICES, MOBIQUITOUS 2023, PT II, 2024, 594 : 393 - 411
  • [48] Novel framework for enhancing security of SDN based VPLS architecture
    Gaur, Kuntal
    Rawat, Umashankar
    Acharya, Saket
    Kumar, Pradeep
    Kalla, Anshuman
    JOURNAL OF DISCRETE MATHEMATICAL SCIENCES & CRYPTOGRAPHY, 2024, 27 (04) : 1331 - 1343
  • [49] BCSDN-IoT: Towards an IoT security architecture based on SDN and Blockchain
    Abbassi, Younes
    Benlahmer, Habib
    INTERNATIONAL JOURNAL OF ELECTRICAL AND COMPUTER ENGINEERING SYSTEMS, 2022, 13 (02) : 155 - 163
  • [50] Dynamic multiphase DDoS attack identification and mitigation framework to secure SDN-based fog-empowered consumer IoT Networks
    Chaudhary, Pooja
    Singh, A. K.
    Gupta, B. B.
    COMPUTERS & ELECTRICAL ENGINEERING, 2025, 123