Explainable Security in SDN-Based IoT Networks

被引:31
作者
Sarica, Alper Kaan [1 ]
Angin, Pelin [1 ]
机构
[1] Middle East Tech Univ, Dept Comp Engn, TR-06800 Ankara, Turkey
关键词
SDN; security; machine learning; 5G; IoT; intrusion detection; INTRUSION DETECTION; SOFTWARE; FRAMEWORK; ATTACK;
D O I
10.3390/s20247326
中图分类号
O65 [分析化学];
学科分类号
070302 ; 081704 ;
摘要
The significant advances in wireless networks in the past decade have made a variety of Internet of Things (IoT) use cases possible, greatly facilitating many operations in our daily lives. IoT is only expected to grow with 5G and beyond networks, which will primarily rely on software-defined networking (SDN) and network functions virtualization for achieving the promised quality of service. The prevalence of IoT and the large attack surface that it has created calls for SDN-based intelligent security solutions that achieve real-time, automated intrusion detection and mitigation. In this paper, we propose a real-time intrusion detection and mitigation solution for SDN, which aims to provide autonomous security in the high-traffic IoT networks of the 5G and beyond era, while achieving a high degree of interpretability by human experts. The proposed approach is built upon automated flow feature extraction and classification of flows while using random forest classifiers at the SDN application layer. We present an SDN-specific dataset that we generated for IoT and provide results on the accuracy of intrusion detection in addition to performance results in the presence and absence of our proposed security mechanism. The experimental results demonstrate that the proposed security approach is promising for achieving real-time, highly accurate detection and mitigation of attacks in SDN-managed IoT networks.
引用
收藏
页码:1 / 30
页数:30
相关论文
共 34 条
[1]   DDoS Attack Mitigation in Internet of Things Using Software De ned Networking [J].
Ahmed, M. Ejaz ;
Kim, Hyoungshick .
2017 THIRD IEEE INTERNATIONAL CONFERENCE ON BIG DATA COMPUTING SERVICE AND APPLICATIONS (IEEE BIGDATASERVICE 2017), 2017, :271-276
[2]   SoftAir: A software defined networking architecture for 5G wireless systems [J].
Akyildiz, Ian F. ;
Wang, Pu ;
Lin, Shih-Chun .
COMPUTER NETWORKS, 2015, 85 :1-18
[3]   Improving Internet of Things (IoT) Security with Software-Defined Networking (SDN) [J].
Al Hayajneh, Abdullah ;
Bhuiyan, Md Zakirul Alam ;
McAndrew, Ian .
COMPUTERS, 2020, 9 (01)
[4]   IoT Botnet Attack Detection Based on Optimized Extreme Gradient Boosting and Feature Selection [J].
Alqahtani, Mnahi ;
Mathkour, Hassan ;
Ben Ismail, Mohamed Maher .
SENSORS, 2020, 20 (21) :1-21
[5]  
Amangele P., 2019, 2019 INT C INFORM TE, P1
[6]   5G network slicing using SDN and NFV: A survey of taxonomy, architectures and future challenges [J].
Barakabitze, Alcardo Alex ;
Ahmad, Arslan ;
Mijumbi, Rashid ;
Hines, Andrew .
COMPUTER NETWORKS, 2020, 167
[7]  
Bhunia SS, 2017, 2017 27TH INTERNATIONAL TELECOMMUNICATION NETWORKS AND APPLICATIONS CONFERENCE (ITNAC), P84
[8]  
Breiman L., 2001, IEEE Trans. Broadcast., V45, P5
[9]   Flow Based Security for IoT Devices using an SDN Gateway [J].
Bull, Peter ;
Austin, Ron ;
Popov, Evgenii ;
Sharma, Mak ;
Watson, Richard .
2016 IEEE 4TH INTERNATIONAL CONFERENCE ON FUTURE INTERNET OF THINGS AND CLOUD (FICLOUD 2016), 2016, :159-165
[10]   Deep learning and software-defined networks: Towards secure IoT architecture [J].
Dawoud, Ahmed ;
Shahristani, Seyed ;
Raun, Chun .
INTERNET OF THINGS, 2018, 3-4 :82-89