A Security Enforcement Framework for SDN Controller Using Game Theoretic Approach

被引:6
|
作者
Priyadarsini, Madhukrishna [1 ]
Bera, Padmalochan [2 ]
Das, Sajal K. [3 ]
Rahman, Mohammad Ashiqur [4 ]
机构
[1] KIIT Deemed Univ, Bhubaneswar 751024, India
[2] Indian Inst Technol, Bhubaneswar 752050, India
[3] Missouri Univ Sci & Technol, Rolla, MO 65409 USA
[4] Florida Int Univ, Miami, FL 33199 USA
基金
俄罗斯基础研究基金会;
关键词
SDN; security; trust model; risk verification; attack model; vulnerability analysis; INTERNET;
D O I
10.1109/TDSC.2022.3158690
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Software-defined networking (SDN) has gained significant attention as the future deployment platform for the Internet and enterprise networks. The major advantages of SDN include effective traffic management, dynamic configuration of policy and flow rules, and better scalability with heterogeneous traffic requirements. However, centralized network control and the use of OpenFlow protocols introduce various security challenges for the underlying network. The attacks on the SDN controller is critical as it hosts all network control functions. Motivated by a systematic analysis of different attack scenarios in SDN using the STRIDE attack model, this article presents an effective security enforcement framework for proactive prevention of potential attacks on SDN controllers. First, based on a signaling game approach, we design a trust-based controller attack detection (TCAD) model that calculates the trust value of each incoming packet to take necessary action. Next, we propose a risk-based attack prevention (RAP) model that detects and filters malicious traffic flows in the network. Finally, we evaluate our proposed security enforcement framework on different scenarios with varying traffic requirements and by injecting attacks based on the STRIDE model. Experimental results show 95% accuracy in the potential attack detection and prevention.
引用
收藏
页码:1500 / 1515
页数:16
相关论文
共 50 条
  • [1] A Simple Security Policy Enforcement System for an Institution Using SDN Controller
    Hadi, Fazal
    Imran, Muhammad
    Durad, Muhammad Hanif
    Waris, Muhammad
    [J]. PROCEEDINGS OF 2018 15TH INTERNATIONAL BHURBAN CONFERENCE ON APPLIED SCIENCES AND TECHNOLOGY (IBCAST), 2018, : 489 - 494
  • [2] Security network policy enforcement through a SDN framework
    Berardi, Davide
    Callegati, Franco
    Melis, Andrea
    Prandini, Marco
    [J]. 2018 28TH INTERNATIONAL TELECOMMUNICATION NETWORKS AND APPLICATIONS CONFERENCE (ITNAC), 2018, : 97 - 100
  • [3] A Game-Theoretic Approach for Network Security Using Honeypots
    Florea, Razvan
    Craus, Mitica
    [J]. FUTURE INTERNET, 2022, 14 (12):
  • [4] A Signalling Game-Based Security Enforcement Mechanism for SDN Controllers
    Priyadarsini, Madhukrishna
    Bera, Padmalochan
    Rahman, M. Ashiqur
    [J]. 2019 10TH INTERNATIONAL CONFERENCE ON COMPUTING, COMMUNICATION AND NETWORKING TECHNOLOGIES (ICCCNT), 2019,
  • [5] A GAME THEORETIC APPROACH TO ROBUST CONTROLLER SYNTHESIS
    MANOUSIOUTHAKIS, V
    [J]. COMPUTERS & CHEMICAL ENGINEERING, 1990, 14 (4-5) : 381 - 389
  • [6] Design of Rollover Prevention Controller Using Game-Theoretic Approach
    Yim, Seongjin
    [J]. TRANSACTIONS OF THE KOREAN SOCIETY OF MECHANICAL ENGINEERS A, 2013, 37 (11) : 1429 - 1436
  • [7] Security in Networks: A Game-Theoretic Approach
    Gueye, Assane
    Walrand, Jean C.
    [J]. 47TH IEEE CONFERENCE ON DECISION AND CONTROL, 2008 (CDC 2008), 2008, : 829 - 834
  • [8] Game Theoretic Security Framework for Quantum Key Distribution
    Krawec, Walter O.
    Miao, Fei
    [J]. DECISION AND GAME THEORY FOR SECURITY, GAMESEC 2018, 2018, 11199 : 38 - 58
  • [9] Quantifying the Security of Physical Facilities: A Game Theoretic Framework
    Singh, Rajdeep
    Ariyur, Kartik B.
    [J]. 2012 50TH ANNUAL ALLERTON CONFERENCE ON COMMUNICATION, CONTROL, AND COMPUTING (ALLERTON), 2012, : 1368 - 1373
  • [10] An Efficient Approach to Robust SDN Controller Placement for Security
    Yang, Shu
    Cui, Laizhong
    Chen, Ziteng
    Xiao, Wei
    [J]. IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2020, 17 (03): : 1669 - 1682