Mitigating DDoS Attacks in SDN-Based IoT Networks Leveraging Secure Control and Data Plane Algorithm

被引:23
作者
Wang, Song [1 ]
Gomez, Karina [1 ]
Sithamparanathan, Kandeepan [1 ]
Asghar, Muhammad Rizwan [2 ]
Russello, Giovanni [2 ]
Zanna, Paul [3 ]
机构
[1] RMIT Univ, Sch Engn, Melbourne, Vic 3000, Australia
[2] Univ Auckland, Cyber Secur Foundry, Auckland 1142, New Zealand
[3] Northbound Networks, Hoppers Crossing, Vic 3029, Australia
来源
APPLIED SCIENCES-BASEL | 2021年 / 11卷 / 03期
关键词
DDoS; SDN; IoT; OpenFlow; Zodiac; security; Packet_In message; TCP; UDP; INTERNET; 5G;
D O I
10.3390/app11030929
中图分类号
O6 [化学];
学科分类号
0703 ;
摘要
Software-Defined Networking (SDN) and Internet of Things (IoT) are the trends of network evolution. SDN mainly focuses on the upper level control and management of networks, while IoT aims to bring devices together to enable sharing and monitoring of real-time behaviours through network connectivity. On the one hand, IoT enables us to gather status of devices and networks and to control them remotely. On the other hand, the rapidly growing number of devices challenges the management at the access and backbone layer and raises security concerns of network attacks, such as Distributed Denial of Service (DDoS). The combination of SDN and IoT leads to a promising approach that could alleviate the management issue. Indeed, the flexibility and programmability of SDN could help in simplifying the network setup. However, there is a need to make a security enhancement in the SDN-based IoT network for mitigating attacks involving IoT devices. In this article, we discuss and analyse state-of-the-art DDoS attacks under SDN-based IoT scenarios. Furthermore, we verify our SDN sEcure COntrol and Data plane (SECOD) algorithm to resist DDoS attacks on the real SDN-based IoT testbed. Our results demonstrate that DDoS attacks in the SDN-based IoT network are easier to detect than in the traditional network due to IoT traffic predictability. We observed that random traffic (UDP or TCP) is more affected during DDoS attacks. Our results also show that the probability of a controller becoming halt is 10%, while the probability of a switch getting unresponsive is 40%.
引用
收藏
页码:1 / 27
页数:27
相关论文
共 54 条
  • [1] DDoS Attack Mitigation in Internet of Things Using Software De ned Networking
    Ahmed, M. Ejaz
    Kim, Hyoungshick
    [J]. 2017 THIRD IEEE INTERNATIONAL CONFERENCE ON BIG DATA COMPUTING SERVICE AND APPLICATIONS (IEEE BIGDATASERVICE 2017), 2017, : 271 - 276
  • [2] A Survey on 5G Networks for the Internet of Things: Communication Technologies and Challenges
    Akpakwu, Godfrey Anuga
    Silva, Bruno J.
    Hancke, Gerhard P.
    Abu-MAhfouz, Adnan M.
    [J]. IEEE ACCESS, 2018, 6 : 3619 - 3647
  • [3] [Anonymous], 2015, TS024 ONF
  • [4] [Anonymous], 2020, GOOGLE
  • [5] Benvenuti C., 2006, Understanding Linux Network Internals
  • [6] Chandrasekharan S., 2018, P NOMS 2018 2018 IEE, P1
  • [7] Chin T, 2015, IEEE MILIT COMMUN C, P659, DOI 10.1109/MILCOM.2015.7357519
  • [8] Connected Car: Technologies, Issues, Future Trends
    Coppola, Riccardo
    Morisio, Maurizio
    [J]. ACM COMPUTING SURVEYS, 2016, 49 (03)
  • [9] A Survey on the Security of Stateful SDN Data Planes
    Dargahi, Tooska
    Caponi, Alberto
    Ambrosin, Moreno
    Bianchi, Giuseppe
    Conti, Mauro
    [J]. IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2017, 19 (03): : 1701 - 1725
  • [10] Dayal N, 2017, INT CONF COMMUN SYST, P274, DOI 10.1109/COMSNETS.2017.7945387