Defending Against New-Flow Attack in SDN-Based Internet of Things

被引:41
|
作者
Xu, Tong [1 ]
Gao, Deyun [1 ]
Dong, Ping [1 ]
Zhang, Hongke [1 ]
Foh, Chuan Heng [2 ]
Chao, Han-Chieh [3 ]
机构
[1] Beijing Jiaotong Univ, Sch Elect & Informat Engn, Natl Engn Lab Next Generat Internet Interconnect, Beijing 100044, Peoples R China
[2] Univ Surrey, Inst Commun Syst, Dept Elect & Elect Engn, IC 5G, Surrey GU1 2UX, England
[3] Natl Dong Hwa Univ, Shoufeng Township 974, Taiwan
来源
IEEE ACCESS | 2017年 / 5卷
关键词
Internet of Things; software-defined networking; OpenFlow; communication system security; new-flow attack; SOFTWARE-DEFINED NETWORKING;
D O I
10.1109/ACCESS.2017.2666270
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Recently, the Internet of Things (IoT) is attracting significant attention from both academia and industry. To connect the huge amount of IoT devices effectively, software-defined networking (SDN) is considered as a promising way because of its centralized network management and programmable routing logic. However, due to the limited resources in both the data plane and the control plane, SDN is vulnerable to the new-flow attack, which can disable the SDN-based IoT by exhausting the switches or the controller. Therefore, in this paper, we propose a smart security mechanism (SSM) to defend against the new-flow attack. The SSM uses the standard southbound and northbound interfaces of SDN, and it includes a low-cost method that monitors the new-flow attack by reusing the asynchronous messages on the control link. The monitor method can differentiate the new-flow attack from the normal flow burst by checking the hit rate of the flow entries. Based on the monitoring result, the SSM uses a dynamic access control method to mitigate the new-flow attack by perceiving the behavior of the security middleware in the IoT. The dynamic access control method can intercept the attack flows at their access switch. Extensive simulations and testbed-based experiments are conducted and the corresponding results verify the feasibility of our claims.
引用
收藏
页码:3431 / 3443
页数:13
相关论文
共 50 条
  • [31] SHSec: SDN based Secure Smart Home Network Architecture for Internet of Things
    Sharma, Pradip Kumar
    Park, Jin Ho
    Jeong, Young-Sik
    Park, Jong Hyuk
    MOBILE NETWORKS & APPLICATIONS, 2019, 24 (03) : 913 - 924
  • [32] SHSec: SDN based Secure Smart Home Network Architecture for Internet of Things
    Pradip Kumar Sharma
    Jin Ho Park
    Young-Sik Jeong
    Jong Hyuk Park
    Mobile Networks and Applications, 2019, 24 : 913 - 924
  • [33] The DAO Induction Attack Against the RPL-based Internet of Things
    Baghani, Ahmad Shabani
    Rahimpour, Sonbol
    Khabbazian, Majid
    2020 28TH INTERNATIONAL CONFERENCE ON SOFTWARE, TELECOMMUNICATIONS AND COMPUTER NETWORKS (SOFTCOM), 2020, : 379 - 383
  • [34] Defending Code from the Internet of Things against Buffer Overflow
    Teixeira, Fernando A.
    Machado, Gustavo V.
    Fonseca, Pablo M.
    Pereira, Fernando M. Q.
    Wong, Hao Chi
    Nogueira, Jose M. S.
    Oliveira, Leonardo B.
    2014 BRAZILIAN SYMPOSIUM ON COMPUTER NETWORKS AND DISTRIBUTED SYSTEMS (SBRC), 2014, : 293 - 301
  • [35] Digital Signature Based Countermeasure Against Puppet Attack in the Internet of Things
    Pu, Cong
    Carpenter, Logan
    2019 IEEE 18TH INTERNATIONAL SYMPOSIUM ON NETWORK COMPUTING AND APPLICATIONS (NCA), 2019, : 189 - 192
  • [36] A flexible SDN-based framework for slow-rate DDoS attack mitigation by reinforcement
    Yungaicela-Naula, Noe M.
    Vargas-Rosales, Cesar
    Perez-Diaz, Jesus Arturo
    Carrera, Diego Fernando
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2022, 205
  • [37] SURFER: A Secure SDN-Based Routing Protocol for Internet of Vehicles
    Mershad, Khaleel
    IEEE INTERNET OF THINGS JOURNAL, 2021, 8 (09) : 7407 - 7422
  • [38] Improving Attack Graph Scalability for the Cloud Through SDN-Based Decomposition and Parallel Processing
    Mjihil, Oussama
    Huang, Dijiang
    Haqiq, Abdelkrim
    UBIQUITOUS NETWORKING, UNET 2017, 2017, 10542 : 193 - 205
  • [39] An Efficient SDN-Based DDoS Attack Detection and Rapid Response Platform in Vehicular Networks
    Yu, Yao
    Guo, Lei
    Liu, Ye
    Zheng, Jian
    Zong, Yue
    IEEE ACCESS, 2018, 6 : 44570 - 44579
  • [40] An Enhanced Flow-Based QoS Management Within Edge Layer for SDN-Based IoT Networking
    Bassene, Avewe
    Gueye, Bamba
    TOWARDS NEW E-INFRASTRUCTURE AND E-SERVICES FOR DEVELOPING COUNTRIES, AFRICOMM 2020, 2021, 361 : 151 - 167