Co-IoT: A Collaborative DDoS mitigation scheme in IoT environment based on blockchain using SDN

被引:51
作者
El Houda, Zakaria Abou [1 ,2 ]
Hafid, Abdelhakim [1 ]
Khoukhi, Lyes [2 ]
机构
[1] Univ Montreal, Dept Comp Sci & Operat Res, Montreal, PQ, Canada
[2] Univ Technol Troyes, ICD ERA, Troyes, France
来源
2019 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM) | 2019年
关键词
IoT; DDoS; SDN; Smart contract; Blockchain; DEFENSE; ATTACKS;
D O I
10.1109/globecom38437.2019.9013542
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The recent proliferation of Internet of Things (IoT) is paving the way for the emergence of smart cities, where billions of IoT devices are interconnected to provide novel pervasive services and automate our daily life tasks (e.g., smart healthcare, smart home). However, as the number of insecure IoT devices continues to grow at a rapid rate, the impact of Distributed Denial-of-Service (DDoS) attacks is growing rapidly. With the advent of IoT botnets such as Mirai, the view towards IoT has changed from enabler of smart cities into a powerful amplifying tool for cyberattacks. This motivates the development of new techniques to provide flexibility and efficiency of decision making on the attack collaboration in a software defined networks (SDN) context. The new emerging technologies, such as SDN and blockchain, give rise to new opportunities for secure, low-cost, flexible and efficient DDoS attacks collaboration for the IoT environment. In this paper, we propose Co-IoT, a blockchain-based framework for collaborative DDoS attack mitigation; it uses smart contracts (i.e., Ethereum's smart contracts) in order to facilitate the attack collaboration among SDN-based domains and transfer attack information's in a secure, efficient and decentralized manner. Co-IoT's implementation is deployed on the Ethereum official test network Ropsten [1]. The experimental results confirm that Co-IoT achieves flexibility, efficiency, security, cost effectiveness making it a promising scheme to mitigate DDoS attacks in large scale.
引用
收藏
页数:6
相关论文
共 24 条
[1]   Collaborative detection of DDoS attacks over multiple network domains [J].
Chen, Yu ;
Hwang, Kai ;
Ku, Wei-Shinn .
IEEE TRANSACTIONS ON PARALLEL AND DISTRIBUTED SYSTEMS, 2007, 18 (12) :1649-1662
[2]  
El Houda Z. A., 2018, 2018 IEEE GLOB COMM, P1, DOI DOI 10.1109/GLOCOM.2018.8647279
[3]  
Etherscan, ETH BLOCK EXPL ROPST
[4]  
Evans D., 2011, The internet of things: how the next evolution of the internet is changing everything. CISCO white paper, DOI DOI 10.1109/IEEESTD.2007.373646
[5]  
Giotis K., 2016, IEEE IFIP NETW OP MA
[6]   Cochain-SC: An Intra- and Inter-Domain Ddos Mitigation Scheme Based on Blockchain Using SDN and Smart Contract [J].
Houda, Zakaria Abou El ;
Hafid, Abdelhakim Senhaji ;
Khoukhi, Lyes .
IEEE ACCESS, 2019, 7 :98893-98907
[7]   JESS: Joint Entropy-Based DDoS Defense Scheme in SDN [J].
Kalkan, Kubra ;
Altay, Levent ;
Gur, Gurkan ;
Alagoz, Fatih .
IEEE JOURNAL ON SELECTED AREAS IN COMMUNICATIONS, 2018, 36 (10) :2358-2372
[8]   Defense Mechanisms Against DDoS Attacks in SDN Environment [J].
Kalkan, Kubra ;
Gur, Gurkan ;
Alagoz, Fatih .
IEEE COMMUNICATIONS MAGAZINE, 2017, 55 (09) :175-179
[9]   SAFETY: Early Detection and Mitigation of TCP SYN Flood Utilizing Entropy in SDN [J].
Kumar, Prashant ;
Tripathi, Meenakshi ;
Nehra, Ajay ;
Conti, Mauro ;
Lal, Chhagan .
IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2018, 15 (04) :1545-1559
[10]  
Nakamoto S., 2008, Bitcoin: A Peer-to-Peer Electronic Cash System