In-network DDoS detection and mitigation using INT data for IoT ecosystem

被引:0
|
作者
Altangerel, Gereltsetseg [1 ]
Tejfel, Mate [1 ]
机构
[1] Eotvos Lorand Univ, Dept Programming Languages & Compilers, Budapest, Hungary
来源
关键词
IoT anomaly detection; data plane; In-band Network Telemetry(INT);
D O I
10.36244/ICJ.2023.5.8
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
Due to the limited capabilities and diversity of Internet of Things (IoT) devices, it is challenging to implement robust and unified security standards for these devices. Additionally, the fact that vulnerable IoT devices are beyond the networks control makes them susceptible to being compromised and used as bots or part of botnets, leading to a surge in attacks involving these devices in recent times. We proposed a real-time IoT anomaly detection and mitigation solution at the programmable data plane in a Software-Defined Networking (SDN) environment using Inband Network telemetry (INT) data to address this issue. As far as we know, it is the first experiment in which INT data is used to detect IoT attacks in the programmable data plane. Based on our performance evaluation, the detection delay of our proposed approach is much lower than the results of previous Distributed Denial-of-Service (DDoS) research, and the detection accuracy is similarly high.
引用
收藏
页码:49 / 54
页数:6
相关论文
共 50 条
  • [1] Towards a Unified In-Network DDoS Detection and Mitigation Strategy
    Friday, Kurt
    Kfoury, Elie
    Bou-Harb, Elias
    Crichigno, Jorge
    PROCEEDINGS OF THE 2020 6TH IEEE CONFERENCE ON NETWORK SOFTWARIZATION (NETSOFT 2020): BRIDGING THE GAP BETWEEN AI AND NETWORK SOFTWARIZATION, 2020, : 218 - 226
  • [2] Patronum: In-network Volumetric DDoS Detection and Mitigation with Programmable Switches
    Wu, Jiahao
    Pan, Heng
    Cui, Penglai
    Huang, Yiwen
    Zhou, Jianer
    He, Peng
    Li, Yanbiao
    Li, Zhenyu
    Xie, Gaogang
    COMPUTER SECURITY-ESORICS 2024, PT IV, 2024, 14985 : 187 - 207
  • [3] LORD: LOw Rate DDoS Attack Detection and Mitigation Using Lightweight Distributed Packet Inspection Agent in IoT Ecosystem
    Bhale, Pradeepkumar
    Biswas, Santosh
    Nandi, Sukumar
    13TH IEEE INTERNATIONAL CONFERENCE ON ADVANCED NETWORKS AND TELECOMMUNICATION SYSTEMS (IEEE ANTS), 2019,
  • [4] Network Security for IoT using SDN: Timely DDoS Detection
    Sambandam, Narmadha
    Hussein, Mourad
    Siddiqi, Noor
    Lung, Chung-Horng
    2018 IEEE CONFERENCE ON DEPENDABLE AND SECURE COMPUTING (DSC), 2018, : 159 - 160
  • [5] IoT-Based DDoS Attack Detection and Mitigation Using the Edge of SDN
    Yang, Yinqi
    Wang, Jian
    Zhai, Baoqin
    Liu, Jiqiang
    CYBERSPACE SAFETY AND SECURITY, PT II, 2019, 11983 : 3 - 17
  • [6] Effective DDoS Mitigation via ML-Driven In-Network Traffic Shaping
    Zhao, Ziming
    Liu, Zhuotao
    Chen, Huan
    Zhang, Fan
    Song, Zhuoxue
    Li, Zhaoxuan
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2024, 21 (04) : 4271 - 4289
  • [7] Euclid: A Fully In-Network, P4-Based Approach for Real-Time DDoS Attack Detection and Mitigation
    Ilha, Alexandre da Silveira
    Lapolli, Angelo Cardoso
    Marques, Jonatas Adilson
    Gaspary, Luciano Paschoal
    IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2021, 18 (03): : 3121 - 3139
  • [8] IoT Network Attack Detection and Mitigation
    Gelenbe, Erol
    Froehlich, Piotr
    Nowak, Mateusz
    Papadopoulos, Stavros
    Protogerou, Aikaterini
    Drosou, Anastasios
    Tzovaras, Dimitrios
    2020 9TH MEDITERRANEAN CONFERENCE ON EMBEDDED COMPUTING (MECO), 2020, : 123 - 128
  • [9] DDoS Mitigation in IoT Using Machine Learning and Blockchain Integration
    Ibrahim El Sayed, Ammar
    Abdelaziz, Mahmoud
    Hussein, Mohamed
    Elbayoumy, Ashraf D.
    IEEE Networking Letters, 2024, 6 (02): : 152 - 155
  • [10] In-network Reinforcement Learning for Attack Mitigation using Programmable Data Plane in SDN
    Ganesan, Aparna
    Sarac, Kamil
    2024 33RD INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATIONS AND NETWORKS, ICCCN 2024, 2024,