Detection and Mitigation of DoS and DDoS Attacks in IoT-Based Stateful SDN: An Experimental Approach

被引:76
|
作者
Galeano-Brajones, Jesus [1 ]
Carmona-Murillo, Javier [1 ]
Valenzuela-Valdes, Juan F. [2 ]
Luna-Valero, Francisco [3 ,4 ]
机构
[1] Univ Extremadura, Dept Comp & Telemat Engn, Merida 06800, Spain
[2] Univ Granada, Dept Signal Theory Telemat & Commun, E-18071 Granada, Spain
[3] Univ Malaga, ITIS Software, E-29071 Malaga, Spain
[4] Univ Malaga, Dept Languages & Comp Sci, E-29071 Malaga, Spain
关键词
stateful SDN; DoS; DDoS; entropy; Internet of Things; experimental evaluation; INTERNET; SECURITY; ENTROPY; NFV;
D O I
10.3390/s20030816
中图分类号
O65 [分析化学];
学科分类号
070302 ; 081704 ;
摘要
The expected advent of the Internet of Things (IoT) has triggered a large demand of embedded devices, which envisions the autonomous interaction of sensors and actuators while offering all sort of smart services. However, these IoT devices are limited in computation, storage, and network capacity, which makes them easy to hack and compromise. To achieve secure development of IoT, it is necessary to engineer scalable security solutions optimized for the IoT ecosystem. To this end, Software Defined Networking (SDN) is a promising paradigm that serves as a pillar in the fifth generation of mobile systems (5G) that could help to detect and mitigate Denial of Service (DoS) and Distributed DoS (DDoS) threats. In this work, we propose to experimentally evaluate an entropy-based solution to detect and mitigate DoS and DDoS attacks in IoT scenarios using a stateful SDN data plane. The obtained results demonstrate for the first time the effectiveness of this technique targeting real IoT data traffic.
引用
收藏
页数:18
相关论文
共 50 条
  • [1] IoT-Based DDoS Attack Detection and Mitigation Using the Edge of SDN
    Yang, Yinqi
    Wang, Jian
    Zhai, Baoqin
    Liu, Jiqiang
    [J]. CYBERSPACE SAFETY AND SECURITY, PT II, 2019, 11983 : 3 - 17
  • [2] Detection and mitigation of DoS attacks in SDN. An experimental approach
    Galeano-Brajones, Jesus
    Cortes-Polo, David
    Valenzuela-Valdes, Juan F.
    Mora, Antonio M.
    Carmona-Murillo, Javier
    [J]. 2019 SIXTH INTERNATIONAL CONFERENCE ON INTERNET OF THINGS: SYSTEMS, MANAGEMENT AND SECURITY (IOTSMS), 2019, : 575 - 580
  • [3] Neural Network-Based Approach for Detection and Mitigation of DDoS Attacks in SDN Environments
    Hannache, Oussama
    Batouche, Mohamed Chaouki
    [J]. INTERNATIONAL JOURNAL OF INFORMATION SECURITY AND PRIVACY, 2020, 14 (03) : 50 - 71
  • [4] SDN-based detection and mitigation of DDoS attacks on smart homes
    Garba, Usman Haruna
    Toosi, Adel N.
    Pasha, Muhammad Fermi
    Khan, Suleman
    [J]. COMPUTER COMMUNICATIONS, 2024, 221 : 29 - 41
  • [5] DNS Amplification Based DDoS Attacks in SDN Environment: Detection and Mitigation
    Gupta, Vishal
    Kochar, Amrit
    Saharan, Shail
    Kulshrestha, Rakhee
    [J]. 2019 IEEE 4TH INTERNATIONAL CONFERENCE ON COMPUTER AND COMMUNICATION SYSTEMS (ICCCS 2019), 2019, : 473 - 478
  • [6] Mitigation against DDoS Attacks on an IoT-Based Production Line Using Machine Learning
    Huraj, Ladislav
    Horak, Tibor
    Strelec, Peter
    Tanuska, Pavol
    [J]. APPLIED SCIENCES-BASEL, 2021, 11 (04): : 1 - 18
  • [7] SDN Based Collaborative Scheme for Mitigation of DDoS Attacks
    Hameed, Sufian
    Khan, Hassan Ahmed
    [J]. FUTURE INTERNET, 2018, 10 (03)
  • [8] IQR-based approach for DDoS detection and mitigation in SDN
    Swami, Rochak
    Dave, Mayank
    Ranga, Virender
    [J]. DEFENCE TECHNOLOGY, 2023, 25 : 76 - 87
  • [9] IQR-based approach for DDoS detection and mitigation in SDN
    Rochak Swami
    Mayank Dave
    Virender Ranga
    [J]. Defence Technology, 2023, 25 (07) : 76 - 87
  • [10] SDN-Based Intrusion Detection System for Early Detection and Mitigation of DDoS Attacks
    Manso, Pedro
    Moura, Jose
    Serrao, Carlos
    [J]. INFORMATION, 2019, 10 (03)