Explainable Security in SDN-Based IoT Networks

被引:25
|
作者
Sarica, Alper Kaan [1 ]
Angin, Pelin [1 ]
机构
[1] Middle East Tech Univ, Dept Comp Engn, TR-06800 Ankara, Turkey
关键词
SDN; security; machine learning; 5G; IoT; intrusion detection; INTRUSION DETECTION; SOFTWARE; FRAMEWORK; ATTACK;
D O I
10.3390/s20247326
中图分类号
O65 [分析化学];
学科分类号
070302 ; 081704 ;
摘要
The significant advances in wireless networks in the past decade have made a variety of Internet of Things (IoT) use cases possible, greatly facilitating many operations in our daily lives. IoT is only expected to grow with 5G and beyond networks, which will primarily rely on software-defined networking (SDN) and network functions virtualization for achieving the promised quality of service. The prevalence of IoT and the large attack surface that it has created calls for SDN-based intelligent security solutions that achieve real-time, automated intrusion detection and mitigation. In this paper, we propose a real-time intrusion detection and mitigation solution for SDN, which aims to provide autonomous security in the high-traffic IoT networks of the 5G and beyond era, while achieving a high degree of interpretability by human experts. The proposed approach is built upon automated flow feature extraction and classification of flows while using random forest classifiers at the SDN application layer. We present an SDN-specific dataset that we generated for IoT and provide results on the accuracy of intrusion detection in addition to performance results in the presence and absence of our proposed security mechanism. The experimental results demonstrate that the proposed security approach is promising for achieving real-time, highly accurate detection and mitigation of attacks in SDN-managed IoT networks.
引用
收藏
页码:1 / 30
页数:30
相关论文
共 50 条
  • [1] Research on SDN-based IoT Security Architecture Model
    Zheng, Shiji
    PROCEEDINGS OF 2019 IEEE 8TH JOINT INTERNATIONAL INFORMATION TECHNOLOGY AND ARTIFICIAL INTELLIGENCE CONFERENCE (ITAIC 2019), 2019, : 575 - 579
  • [2] SDN-Based Security Framework for the IoT in Distributed Grid
    Gonzalez, Carlos
    Charfadine, Salim Mahamat
    Flauzac, Olivier
    Nolot, Florent
    2016 INTERNATIONAL MULTIDISCIPLINARY CONFERENCE ON COMPUTER AND ENERGY SCIENCE (SPLITECH), 2016, : 81 - 85
  • [3] Exploring Blockchain-driven security in SDN-based IoT networks
    Indrason, Ngangbam
    Saha, Goutam
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2024, 224
  • [4] Privacy-Preserving and Security in SDN-Based IoT: A Survey
    Ahmadvand, Hossein
    Lal, Chhagan
    Hemmati, Hadi
    Sookhak, Mehdi
    Conti, Mauro
    IEEE ACCESS, 2023, 11 : 44772 - 44786
  • [5] SDN-based Predictive Alarm Manager for Security Attacks Detection at the IoT Gateways
    Thorat, Pankaj
    Dubey, Niraj Kumar
    Khetan, Kunal
    Challa, Rajesh
    2021 IEEE 18TH ANNUAL CONSUMER COMMUNICATIONS & NETWORKING CONFERENCE (CCNC), 2021,
  • [6] An SDN-based Firewall for Networks with Varying Security Requirements
    Rezaei, Ghazal
    Hashemi, Massoud Reza
    2021 26TH INTERNATIONAL COMPUTER CONFERENCE, COMPUTER SOCIETY OF IRAN (CSICC), 2021,
  • [7] Enabling Virtual AAA Management in SDN-Based IoT Networks
    Molina Zarca, Alejandro
    Garcia-Carrillo, Dan
    Bernal Bernabe, Jorge
    Ortiz, Jordi
    Marin-Perez, Rafael
    Skarmeta, Antonio
    SENSORS, 2019, 19 (02)
  • [8] Security Architecture for Defining and Enforcing Security Profiles in DLT/SDN-Based IoT Systems
    Matheu, Sara N.
    Robles Enciso, Alberto
    Molina Zarca, Alejandro
    Garcia-Carrillo, Dan
    Luis Hernandez-Ramos, Jose
    Bernal Bernabe, Jorge
    Skarmeta, Antonio F.
    SENSORS, 2020, 20 (07)
  • [9] OpenStackDP: a scalable network security framework for SDN-based OpenStack cloud infrastructure
    Krishnan, Prabhakar
    Jain, Kurunandan
    Aldweesh, Amjad
    Prabu, P.
    Buyya, Rajkumar
    JOURNAL OF CLOUD COMPUTING-ADVANCES SYSTEMS AND APPLICATIONS, 2023, 12 (01):
  • [10] CyberShip-IoT: A dynamic and adaptive SDN-based security policy enforcement framework for ships
    Sahay, Rishikesh
    Meng, Weizhi
    Estay, D. A. Sepulveda
    Jensen, Christian D.
    Barfod, Michael Bruhn
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2019, 100 : 736 - 750