Quarantining Malicious IoT Devices in Intelligent Sliced Mobile Networks

被引:4
作者
Candal-Ventureira, David [1 ]
Fondo-Ferreiro, Pablo [1 ]
Gil-Castineira, Felipe [1 ]
Javier Gonzalez-Castano, Francisco [1 ]
机构
[1] Univ Vigo, AtlanTTic Res Ctr Telecommun Technol, Informat Technol Grp, Vigo 36310, Spain
关键词
internet of things; 5G; network slicing; malware; denial of service; SOFTWARE-DEFINED NETWORKING; 5G MOBILE; ARCHITECTURES; SDN;
D O I
10.3390/s20185054
中图分类号
O65 [分析化学];
学科分类号
070302 ; 081704 ;
摘要
The unstoppable adoption of the Internet of Things (IoT) is driven by the deployment of new services that require continuous capture of information from huge populations of sensors, or actuating over a myriad of "smart" objects. Accordingly, next generation networks are being designed to support such massive numbers of devices and connections. For example, the 3rd Generation Partnership Project (3GPP) is designing the different 5G releases specifically with IoT in mind. Nevertheless, from a security perspective this scenario is a potential nightmare: the attack surface becomes wider and many IoT nodes do not have enough resources to support advanced security protocols. In fact, security is rarely a priority in their design. Thus, including network-level mechanisms for preventing attacks from malware-infected IoT devices is mandatory to avert further damage. In this paper, we propose a novel Software-Defined Networking (SDN)-based architecture to identify suspicious nodes in 4G or 5G networks and redirect their traffic to a secondary network slice where traffic is analyzed in depth before allowing it reaching its destination. The architecture can be easily integrated in any existing deployment due to its interoperability. By following this approach, we can detect potential threats at an early stage and limit the damage by Distributed Denial of Service (DDoS) attacks originated in IoT devices.
引用
收藏
页码:1 / 18
页数:18
相关论文
共 42 条
  • [11] Fondo-Ferreiro P., 2009, ARXIV2009200901716
  • [12] Geller M., 2018, CISC VIS NETW IND GL
  • [13] New 3GPP Standard for IoT
    Gozalvez, Javier
    [J]. IEEE VEHICULAR TECHNOLOGY MAGAZINE, 2016, 11 (01): : 14 - 20
  • [14] Haugen T., 2020, U.S. Patent, Patent No. [2020/0037163 A1, 20200037163]
  • [15] NFV: State of the Art, Challenges, and Implementation in Next Generation Mobile Networks (vEPC)
    Hawilo, Hassan
    Shami, Abdallah
    Mirahmadi, Maysam
    Asal, Rasool
    [J]. IEEE NETWORK, 2014, 28 (06): : 18 - 26
  • [16] JESS: Joint Entropy-Based DDoS Defense Scheme in SDN
    Kalkan, Kubra
    Altay, Levent
    Gur, Gurkan
    Alagoz, Fatih
    [J]. IEEE JOURNAL ON SELECTED AREAS IN COMMUNICATIONS, 2018, 36 (10) : 2358 - 2372
  • [17] Network Slices toward 5G Communications: Slicing the LTE Network
    Katsalis, Kostas
    Nikaein, Navid
    Schiller, Eryk
    Ksentini, Adlen
    Braun, Torsten
    [J]. IEEE COMMUNICATIONS MAGAZINE, 2017, 55 (08) : 146 - 154
  • [18] Flow Setup Latency in SDN Networks
    Khalili, Ramin
    Despotovic, Zoran
    Hecker, Artur
    [J]. IEEE JOURNAL ON SELECTED AREAS IN COMMUNICATIONS, 2018, 36 (12) : 2631 - 2639
  • [19] IoT security: Review, blockchain solutions, and open challenges
    Khan, Minhaj Ahmad
    Salah, Khaled
    [J]. FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2018, 82 : 395 - 411
  • [20] Software-Defined Networking: A Comprehensive Survey
    Kreutz, Diego
    Ramos, Fernando M. V.
    Verissimo, Paulo Esteves
    Rothenberg, Christian Esteve
    Azodolmolky, Siamak
    Uhlig, Steve
    [J]. PROCEEDINGS OF THE IEEE, 2015, 103 (01) : 14 - 76