Defending Against New-Flow Attack in SDN-Based Internet of Things

被引:41
|
作者
Xu, Tong [1 ]
Gao, Deyun [1 ]
Dong, Ping [1 ]
Zhang, Hongke [1 ]
Foh, Chuan Heng [2 ]
Chao, Han-Chieh [3 ]
机构
[1] Beijing Jiaotong Univ, Sch Elect & Informat Engn, Natl Engn Lab Next Generat Internet Interconnect, Beijing 100044, Peoples R China
[2] Univ Surrey, Inst Commun Syst, Dept Elect & Elect Engn, IC 5G, Surrey GU1 2UX, England
[3] Natl Dong Hwa Univ, Shoufeng Township 974, Taiwan
来源
IEEE ACCESS | 2017年 / 5卷
关键词
Internet of Things; software-defined networking; OpenFlow; communication system security; new-flow attack; SOFTWARE-DEFINED NETWORKING;
D O I
10.1109/ACCESS.2017.2666270
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Recently, the Internet of Things (IoT) is attracting significant attention from both academia and industry. To connect the huge amount of IoT devices effectively, software-defined networking (SDN) is considered as a promising way because of its centralized network management and programmable routing logic. However, due to the limited resources in both the data plane and the control plane, SDN is vulnerable to the new-flow attack, which can disable the SDN-based IoT by exhausting the switches or the controller. Therefore, in this paper, we propose a smart security mechanism (SSM) to defend against the new-flow attack. The SSM uses the standard southbound and northbound interfaces of SDN, and it includes a low-cost method that monitors the new-flow attack by reusing the asynchronous messages on the control link. The monitor method can differentiate the new-flow attack from the normal flow burst by checking the hit rate of the flow entries. Based on the monitoring result, the SSM uses a dynamic access control method to mitigate the new-flow attack by perceiving the behavior of the security middleware in the IoT. The dynamic access control method can intercept the attack flows at their access switch. Extensive simulations and testbed-based experiments are conducted and the corresponding results verify the feasibility of our claims.
引用
收藏
页码:3431 / 3443
页数:13
相关论文
共 50 条
  • [41] BDF-SDN: A Big Data Framework for DDoS Attack Detection in Large-Scale SDN-Based Cloud
    Phuc Trinh Dinh
    Park, Minho
    2021 IEEE CONFERENCE ON DEPENDABLE AND SECURE COMPUTING (DSC), 2021,
  • [42] An EMD and ARMA-based network traffic prediction approach in SDN-based internet of vehicles
    Tian, Miao
    Sun, Chen
    Wu, Shaozhi
    WIRELESS NETWORKS, 2021,
  • [43] Identifying attack signatures for the Internet of Things An IP flow based approach
    Vieira, Leandro
    Santos, Leonel
    Goncalves, Ramiro
    Rabadao, Carlos
    2019 14TH IBERIAN CONFERENCE ON INFORMATION SYSTEMS AND TECHNOLOGIES (CISTI), 2019,
  • [44] DIO Suppression Attack Against Routing in the Internet of Things
    Perazzo, Pericle
    Vallati, Carlo
    Anastasi, Giuseppe
    Dini, Gianluca
    IEEE COMMUNICATIONS LETTERS, 2017, 21 (11) : 2524 - 2527
  • [45] A Gini Index-Based Countermeasure Against Sybil Attack in the Internet of Things
    Groves, Bryan
    Pu, Cong
    MILCOM 2019 - 2019 IEEE MILITARY COMMUNICATIONS CONFERENCE (MILCOM), 2019,
  • [46] Empowering SDN-Docker Based Architecture for Internet of Things Heterogeneity
    Bedhief, Intidhar
    Kassar, Meriem
    Aguili, Taoufik
    JOURNAL OF NETWORK AND SYSTEMS MANAGEMENT, 2023, 31 (01)
  • [47] SDN-based Edge Computing Security: Detecting and Mitigating Flow Rule Attacks
    Sen Baidya, Sonali
    Hewett, Rattikorn
    SEC'19: PROCEEDINGS OF THE 4TH ACM/IEEE SYMPOSIUM ON EDGE COMPUTING, 2019, : 364 - 370
  • [48] An hybrid and proactive architecture based on SDN for Internet of Things
    Bendouda, Djamila
    Rachedi, Abderrezak
    Haffaf, Hafid
    2017 13TH INTERNATIONAL WIRELESS COMMUNICATIONS AND MOBILE COMPUTING CONFERENCE (IWCMC), 2017, : 951 - 956
  • [49] SDN-based Mitigation of Scanning Attacks for the 5G Internet of Radio Light System
    Cabaj, Krzysztof
    Gregorczyk, Marcin
    Mazurczyk, Wojciech
    Nowakowski, Piotr
    Zorawski, Piotr
    13TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY (ARES 2018), 2019,
  • [50] TPEFD:an SDN-based efficient elephant flow detection method
    TIAN Yu
    LIU Jing
    LAI Yingxu
    BAO Zhenshan
    ZHANG Wenbo
    网络与信息安全学报, 2017, 3 (05) : 70 - 76