Defending Against New-Flow Attack in SDN-Based Internet of Things

被引:41
|
作者
Xu, Tong [1 ]
Gao, Deyun [1 ]
Dong, Ping [1 ]
Zhang, Hongke [1 ]
Foh, Chuan Heng [2 ]
Chao, Han-Chieh [3 ]
机构
[1] Beijing Jiaotong Univ, Sch Elect & Informat Engn, Natl Engn Lab Next Generat Internet Interconnect, Beijing 100044, Peoples R China
[2] Univ Surrey, Inst Commun Syst, Dept Elect & Elect Engn, IC 5G, Surrey GU1 2UX, England
[3] Natl Dong Hwa Univ, Shoufeng Township 974, Taiwan
来源
IEEE ACCESS | 2017年 / 5卷
关键词
Internet of Things; software-defined networking; OpenFlow; communication system security; new-flow attack; SOFTWARE-DEFINED NETWORKING;
D O I
10.1109/ACCESS.2017.2666270
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Recently, the Internet of Things (IoT) is attracting significant attention from both academia and industry. To connect the huge amount of IoT devices effectively, software-defined networking (SDN) is considered as a promising way because of its centralized network management and programmable routing logic. However, due to the limited resources in both the data plane and the control plane, SDN is vulnerable to the new-flow attack, which can disable the SDN-based IoT by exhausting the switches or the controller. Therefore, in this paper, we propose a smart security mechanism (SSM) to defend against the new-flow attack. The SSM uses the standard southbound and northbound interfaces of SDN, and it includes a low-cost method that monitors the new-flow attack by reusing the asynchronous messages on the control link. The monitor method can differentiate the new-flow attack from the normal flow burst by checking the hit rate of the flow entries. Based on the monitoring result, the SSM uses a dynamic access control method to mitigate the new-flow attack by perceiving the behavior of the security middleware in the IoT. The dynamic access control method can intercept the attack flows at their access switch. Extensive simulations and testbed-based experiments are conducted and the corresponding results verify the feasibility of our claims.
引用
收藏
页码:3431 / 3443
页数:13
相关论文
共 50 条
  • [1] Performance Evaluation of SDN-based Internet of Space Things
    Kak, Ahan
    Guven, Eray
    Ergin, Utku E.
    Akyildiz, Ian F.
    2018 IEEE GLOBECOM WORKSHOPS (GC WKSHPS), 2018,
  • [2] SHIOT: A Novel SDN-based Framework for the Heterogeneous Internet of Things
    Hai-Anh Tran
    Duc Tran
    Linh-Giang Nguyen
    Quoc-Trung Ha
    Van Tong
    Mellouk, Abdelhamid
    INFORMATICA-JOURNAL OF COMPUTING AND INFORMATICS, 2018, 42 (03): : 313 - 323
  • [3] An SDN-based Approach For Defending Against Reflective DDoS Attacks
    Lukaseder, Thomas
    StOlzle, Kevin
    Kleber, Stephan
    Erb, Benjamin
    Kargl, Frank
    PROCEEDINGS OF THE 2018 IEEE 43RD CONFERENCE ON LOCAL COMPUTER NETWORKS (LCN), 2018, : 299 - 302
  • [4] Mitigating New-Flow Attack with SDNSnapshot in P4-based SDN
    Cai, Yun-Zhan
    Lin, Ting-Yu
    Wang, Yu-Ting
    Tuan, Ya-Pei
    Tsai, Meng-Hsun
    2022 23RD ASIA-PACIFIC NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM (APNOMS 2022), 2022, : 227 - 230
  • [5] An SDN-based Network Architecture for Internet of Things
    Zhang, Zhiyong
    Wang, Rui
    Cai, Xiaojun
    Jia, Zhiping
    IEEE 20TH INTERNATIONAL CONFERENCE ON HIGH PERFORMANCE COMPUTING AND COMMUNICATIONS / IEEE 16TH INTERNATIONAL CONFERENCE ON SMART CITY / IEEE 4TH INTERNATIONAL CONFERENCE ON DATA SCIENCE AND SYSTEMS (HPCC/SMARTCITY/DSS), 2018, : 980 - 985
  • [6] Application-Aware SDN-Based Iterative Reconfigurable Routing Protocol for Internet of Things (IoT)
    Shafique, Ayesha
    Cao, Guo
    Aslam, Muhammad
    Asad, Muhammad
    Ye, Dengpan
    SENSORS, 2020, 20 (12) : 1 - 22
  • [7] An adaptive data coding scheme for energy consumption reduction in SDN-based Internet of Things
    Salehi, Shahab
    Farbeh, Hamed
    Rokhsari, Alireza
    COMPUTER NETWORKS, 2023, 221
  • [8] Routing Optimization For Cloud Services in SDN-based Internet of Things With TCAM Capacity Constraint
    Xu, Shizhong
    Wang, Xiong
    Yang, Guangxu
    Ren, Jing
    Wang, Sheng
    JOURNAL OF COMMUNICATIONS AND NETWORKS, 2020, 22 (02) : 145 - 158
  • [9] Defending SDN-based IoT Networks Against DDoS Attacks Using Markov Decision Process
    Zheng, Jianjun
    Namin, Akbar Siami
    2018 IEEE INTERNATIONAL CONFERENCE ON BIG DATA (BIG DATA), 2018, : 4589 - 4592
  • [10] New-flow based DDoS attacks in SDN: Taxonomy, rationales, and research challenges
    Singh, Maninder Pal
    Bhandari, Abhinav
    COMPUTER COMMUNICATIONS, 2020, 154 (154) : 509 - 527