A Security Policy Protocol for Detection and Prevention of Internet Control Message Protocol Attacks in Software Defined Networks

被引:20
|
作者
Onyema, Edeh Michael [1 ,2 ]
Kumar, M. Anand [3 ]
Balasubaramanian, Sundaravadivazhagn [4 ]
Bharany, Salil [5 ]
Rehman, Ateeq Ur [6 ]
Eldin, Elsayed Tag [7 ]
Shafiq, Muhammad [8 ]
机构
[1] Alex Ekwueme Fed Univ, Fac Educ, Dept Vocat & Tech Educ, PMB 1010, Ndufu Alike, Abakaliki, Nigeria
[2] Saveetha Inst Med & Tech Sci, Saveetha Sch Engn, Chennai 602105, Tamil Nadu, India
[3] Graph Era Deemed Univ, Dept Comp Applicat, Dehra Dun 248002, Uttarakhand, India
[4] Univ Technol & Appl Sci, Dept Informat Technol, POB 191, Al Mussanah 314, Oman
[5] Guru Nanak Dev Univ, Dept Comp Engn & Technol, Amritsar 143005, Punjab, India
[6] Govt Coll Univ, Dept Elect Engn, Lahore 54000, Pakistan
[7] Future Univ Egypt New Cairo, Fac Engn & Technol, New Cairo 11835, Egypt
[8] Yeungnam Univ, Dept Informat & Commun Engn, Gyongsan 38541, South Korea
关键词
bandwidth; attacks; controller; flooding; ICMP; security; software-defined networks; virtualization; PACKET INJECTION ATTACK; OPTICAL NETWORKS; DEFENSE;
D O I
10.3390/su141911950
中图分类号
X [环境科学、安全科学];
学科分类号
08 ; 0830 ;
摘要
Owing to the latest advancements in networking devices and functionalities, there is a need to build future intelligent networks that provide intellectualization, activation, and customization. Software-defined networks (SDN) are one of the latest and most trusted technologies that provide a method of network management that provides network virtualization. Although traditional networks still have a strong presence in the industry, software-defined networks have begun to replace them at faster rates. When network technologies emerge at a steady rate, SDN will be implemented at higher rates in the upcoming years in all fields. Although SDN technology removes the complexity of tying control and data plane together over traditional networks, certain aspects such as security, controllability, and economy of network resources are vulnerable. Among these aspects, security is one of the main concerns that are to be viewed seriously as far as the applications of SDN are concerned. This paper presents the most recent security issues SDN environment followed by preventive mechanisms. This study focuses on Internet control message protocol (ICMP) attacks in SDN networks. This study proposes a security policy protocol (SPP) to detect attacks that target devices such as switches and the SDN controller in the SDN networks. The mechanism is based on ICMP attacks, which are the main source of flooding attacks in the SDN networks. The proposed model focuses on two aspects: security policy process verification and client authentication verification. Experimental results shows that the proposed model can effectively defend against flooding attacks in SDN network environments.
引用
收藏
页数:19
相关论文
共 50 条
  • [1] Detection and Prevention of DoS attacks in Software-Defined Cloud Networks
    Rengaraju, Perumalraja
    Ramanan, Raja, V
    Lung, Chung-Horng
    [J]. 2017 IEEE CONFERENCE ON DEPENDABLE AND SECURE COMPUTING, 2017, : 217 - 223
  • [2] GaTeBaSep: game theory-based security protocol against ARP spoofing attacks in software-defined networks
    Fabrice Mvah
    Vianney Kengne Tchendji
    Clémentin Tayou Djamegni
    Ahmed H. Anwar
    Deepak K. Tosh
    Charles Kamhoua
    [J]. International Journal of Information Security, 2024, 23 : 373 - 387
  • [3] GaTeBaSep: game theory-based security protocol against ARP spoofing attacks in software-defined networks
    Mvah, Fabrice
    Tchendji, Vianney Kengne
    Djamegni, Clementin Tayou
    Anwar, Ahmed H.
    Tosh, Deepak K.
    Kamhoua, Charles
    [J]. INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2024, 23 (01) : 373 - 387
  • [4] SafeFlow: Authentication Protocol For Software Defined Networks
    Allouzi, Maha Ali
    Khan, Javed I.
    [J]. 2018 IEEE 12TH INTERNATIONAL CONFERENCE ON SEMANTIC COMPUTING (ICSC), 2018, : 374 - 376
  • [5] An Approach for Detection of Attacks in Software Defined Networks
    Chippalkatti, Omkar
    Nimbhorkar, S. U.
    [J]. 2017 INTERNATIONAL CONFERENCE ON INNOVATIONS IN INFORMATION, EMBEDDED AND COMMUNICATION SYSTEMS (ICIIECS), 2017,
  • [6] A Policy-based Interaction Protocol between Software Defined Security Controller and Virtual Security Functions
    Farahmandian, Sara
    Hoang, Doan B.
    [J]. 2020 FOURTH CYBER SECURITY IN NETWORKING CONFERENCE (CSNET), 2020,
  • [7] A Novel Mechanism for Detection of Address Resolution Protocol Spoofing Attacks in Large-Scale Software-Defined Networks
    Patrice, Laurent
    Sinde, Ramadhani
    Leo, Judith
    [J]. IEEE ACCESS, 2024, 12 : 80255 - 80265
  • [8] Mitigating Slow Hypertext Transfer Protocol Distributed Denial of Service Attacks in Software Defined Networks
    Akanji, Oluwatobi Shadrach
    Abisoye, Opeyemi Aderiike
    Iliyasu, Mohammed Awwal
    [J]. JOURNAL OF INFORMATION AND COMMUNICATION TECHNOLOGY-MALAYSIA, 2021, 20 (03): : 277 - 304
  • [9] Deploying Internet Protocol Security in satellite networks using Transmission Control Protocol Performance Enhancing Proxies
    Caubet, Juan
    Munoz, Jose L.
    Alins, Juanjo
    Mata-Diaz, Jorge
    Esparza, Oscar
    [J]. INTERNATIONAL JOURNAL OF SATELLITE COMMUNICATIONS AND NETWORKING, 2013, 31 (02) : 51 - 76
  • [10] Protocol Stack Mapping of Software Defined Protocol for Next Generation Mobile Networks
    Wen, Ruihan
    Feng, Gang
    Tan, Wei
    Ni, Rui
    Cao, Wei
    Qin, Shuang
    [J]. 2016 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2016,