Edge security for SIP-enabled IoT devices with P4

被引:9
|
作者
Febro, Aldo [1 ]
Xiao, Hannan [2 ]
Spring, Joseph [1 ]
Christianson, Bruce [1 ]
机构
[1] Univ Hertfordshire, Dept Comp Sci, Hatfield AL10 9AB, Herts, England
[2] Kings Coll London, Dept Informat, London WC2B 4BG, England
关键词
SIP; DDoS; Dictionary attack; IoT; P4; VNF; SIPVicious; Edge computing; INTERNET; DDOS;
D O I
10.1016/j.comnet.2021.108698
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
The exponential growth of IoT devices poses security concerns, in part because they provide a fertile breeding ground for botnets. For example, the Mirai botnet infected almost 65,000 devices in its first 20 h. With the prevalence of Session Initiation Protocol (SIP) phones and devices on the networks today, the attacker could easily target and recruit these IoT devices as bots. Conventional network security measures do not provide adequate attack prevention, detection, and mitigation for these widely distributed IoT devices. This paper presents microVNF, a Virtualized Network Function (VNF) that leverages the programmable data plane feature on the edge switch. Based on knowledge gained from the Mirai botnet incident and following the defense-in-depth principle, microVNF protects IoT devices against SIP DDoS attacks in two stages: before and after infection. Prior to infection, it protects against SIP scanning, enumeration, and dictionary attacks. After infection, microVNF blocks botnet registration attempts to the command-and-control (CNC) server, thereby preventing the botnet from receiving commands sent from the CNC server, and detects and mitigates botnet SIP DDoS attacks. We conducted six experiments that involved using popular attack tools against microVNF, and it successfully performed deep-packet inspection of unencrypted SIP packets so as to track anomalies from a typical SIP statemachine. In this use case, besides providing physical connectivity to the IoT devices, the edge switch containing microVNF also provides the first line of defense in stopping malicious packets from propagating upstream to the core network. In addition to securing SIP, the microVNF approach can be adapted to other text-based, application-layer protocols such as HTTP and SMTP. MicroVNF leverages the native capability of programmable data planes without depending on external devices, thereby making this approach practical for securing edgecomputing environments against application-layer attacks.
引用
收藏
页数:25
相关论文
共 50 条
  • [1] Distributed SIP DDoS Defense with P4
    Febro, Aldo
    Xiao, Hannan
    Spring, Joseph
    2019 IEEE WIRELESS COMMUNICATIONS AND NETWORKING CONFERENCE (WCNC), 2019,
  • [2] P4 Edge Node Enabling Stateful Traffic Engineering and Cyber Security
    Paolucci, F.
    Civerchia, F.
    Sgambelluri, A.
    Giorgetti, A.
    Cugini, F.
    Castoldi, P.
    JOURNAL OF OPTICAL COMMUNICATIONS AND NETWORKING, 2019, 11 (01) : A84 - A95
  • [3] Security at the Edge for Resource-Limited IoT Devices
    Canavese, Daniele
    Mannella, Luca
    Regano, Leonardo
    Basile, Cataldo
    SENSORS, 2024, 24 (02)
  • [4] Security Middleware Programming Using P4
    Voeroes, Peter
    Kiss, Attila
    HUMAN ASPECTS OF INFORMATION SECURITY, PRIVACY, AND TRUST, 2016, 9750 : 277 - 287
  • [5] Emotion Detection IoT enabled Edge-node for Citizen Security
    Bhattacherjee, Subhra Shankha
    Kumar, Sanju N. T.
    Rajalakshmi, P.
    2019 IEEE 5TH WORLD FORUM ON INTERNET OF THINGS (WF-IOT), 2019, : 925 - 930
  • [6] P4NFV: P4 Enabled NFV Systems with SmartNlCs
    Mohammadkhan, Ali
    Panda, Sourav
    Kulkarni, Sameer G.
    Ramakrishnan, K. K.
    Bhuyan, Laxmi N.
    2019 IEEE CONFERENCE ON NETWORK FUNCTION VIRTUALIZATION AND SOFTWARE DEFINED NETWORKS (IEEE NFV-SDN), 2019,
  • [7] Edge Machine Learning for AI-Enabled IoT Devices: A Review
    Merenda, Massimo
    Porcaro, Carlo
    Iero, Demetrio
    SENSORS, 2020, 20 (09)
  • [8] Blockchain Enabled IoT Edge Computing: Addressing Privacy, Security and other Challenges
    Mendki, Pankaj
    2020 2ND INTERNATIONAL CONFERENCE ON BLOCKCHAIN TECHNOLOGY (ICBCT 2020), 2020, : 63 - 67
  • [9] Security applications in P4: Implementation and lessons learned
    Mazloum, Ali
    Alsabeh, Ali
    Kfoury, Elie
    Crichigno, Jorge
    COMPUTER NETWORKS, 2025, 257
  • [10] New Security State Awareness Model for IoT Devices With Edge Intelligence
    Lei, Wenxin
    Wen, Hong
    Hou, Wenjing
    Xu, Xinchen
    IEEE ACCESS, 2021, 9 : 69756 - 69765