A novel mechanism to handle address spoofing attacks in SDN based IoT

被引:35
作者
Aldabbas, Hamza [1 ]
Amin, Rashid [2 ]
机构
[1] Al Balqa Appl Univ, Prince Abdullah Bin Ghazi Fac Informat & Commun T, Software Engn Dept, Al Salt, Jordan
[2] Univ Engn & Technol, Dept Comp Sci, Taxila, Pakistan
来源
CLUSTER COMPUTING-THE JOURNAL OF NETWORKS SOFTWARE TOOLS AND APPLICATIONS | 2021年 / 24卷 / 04期
关键词
ARP spoofing; Internet of things (IoT); Network security; Port blocking; SDN based IoT; SOFTWARE-DEFINED NETWORKING; HYBRID; INTERNET; THINGS;
D O I
10.1007/s10586-021-03309-0
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The Internet of Things (IoT) is a network of devices (servers, sensors, nodes, and so on) used to conduct tasks like health monitoring, production monitoring, business transactions, etc. In IoT, the traditional networking paradigm in which the control and data planes are vertically integrated is utilized to link various types of networks. Software Defined Networking (SDN) is a relatively new concept that separates the control plane from the data plane, making network management and maintenance easier. In SDN, network operators prioritise the security of the overall system. The most severe attacks on systems target the Address Resolution Protocol (ARP), which then frequently act as a springboard for more complicated attacks. This paper proposes a secure SDN-based IoT architecture to manage and reduce ARP spoofing attacks by deploying a new machine near the SDN controller to handle address resolution questions. To examine address spoofing threats, we move ARP traffic to this new machine. This module works in tandem with the controller, gathering topology data and ARP requests in order to detect potential attack conditions. The ARP data is analyzed using custom methods. According to simulation results, the proposed technique increases network throughput, improves attack detection and mitigation time by 35% over existing techniques.
引用
收藏
页码:3011 / 3026
页数:16
相关论文
共 28 条
[1]   Enforcing Optimal ACL Policies Using K-Partite Graph in Hybrid SDN [J].
Amin, Rashid ;
Shah, Nadir ;
Mehmood, Wagar .
ELECTRONICS, 2019, 8 (06)
[2]   Hybrid SDN Networks: A Survey of Existing Approaches [J].
Amin, Rashid ;
Reisslein, Martin ;
Shah, Nadir .
IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2018, 20 (04) :3259-3306
[3]   Auto-Configuration of ACL Policy in Case of Topology Change in Hybrid SDN [J].
Amin, Rashid ;
Shah, Nadir ;
Shah, Babar ;
Alfandi, Omar .
IEEE ACCESS, 2016, 4 :9437-9450
[4]   Averaged dependence estimators for DoS attack detection in IoT networks [J].
Baig, Zubair A. ;
Sanguanpong, Surasak ;
Firdous, Syed Naeem ;
Van Nhan Vo ;
Tri Gia Nguyen ;
So-In, Chakchai .
FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2020, 102 :198-209
[5]   Software-Defined Networking for Internet of Things: A Survey [J].
Bera, Samaresh ;
Misra, Sudip ;
Vasilakos, Athanasios V. .
IEEE INTERNET OF THINGS JOURNAL, 2017, 4 (06) :1994-2008
[6]  
Cox J.H., 2016, SoutheastCon 2016, P1, DOI [10.1109/SECON.2016.7506644, 10.1109/secon.2016.7506644]
[7]   A Survey on Future Internet Security Architectures [J].
Ding, Wenxiu ;
Yang, Zheng ;
Deng, Robert H. .
IEEE ACCESS, 2016, 4 :4374-4393
[8]   Analysis of Security Mechanisms Based on Clusters IoT Environments [J].
Gaona-Garcia, Paulo ;
Montenegro-Marin, Carlos ;
David Prieto, Juan ;
Vanessa Nieto, Yuri .
INTERNATIONAL JOURNAL OF INTERACTIVE MULTIMEDIA AND ARTIFICIAL INTELLIGENCE, 2017, 4 (03) :55-60
[9]  
Hay B, 2019, P 52 HAW INT C SYST
[10]   A Front-End Electronics Prototype Based on Gigabit Ethernet for the ATLAS Small-Strip Thin Gap Chamber [J].
Hu, Kun ;
Lu, Houbing ;
Wang, Xu ;
Li, Feng ;
Wang, Xinxin ;
Geng, Tianru ;
Yang, Hang ;
Liu, Shengquan ;
Han, Liang ;
Jin, Ge .
IEEE TRANSACTIONS ON NUCLEAR SCIENCE, 2017, 64 (06) :1232-1237