Detection and Mitigation of DoS and DDoS Attacks in IoT-Based Stateful SDN: An Experimental Approach

被引:76
|
作者
Galeano-Brajones, Jesus [1 ]
Carmona-Murillo, Javier [1 ]
Valenzuela-Valdes, Juan F. [2 ]
Luna-Valero, Francisco [3 ,4 ]
机构
[1] Univ Extremadura, Dept Comp & Telemat Engn, Merida 06800, Spain
[2] Univ Granada, Dept Signal Theory Telemat & Commun, E-18071 Granada, Spain
[3] Univ Malaga, ITIS Software, E-29071 Malaga, Spain
[4] Univ Malaga, Dept Languages & Comp Sci, E-29071 Malaga, Spain
关键词
stateful SDN; DoS; DDoS; entropy; Internet of Things; experimental evaluation; INTERNET; SECURITY; ENTROPY; NFV;
D O I
10.3390/s20030816
中图分类号
O65 [分析化学];
学科分类号
070302 ; 081704 ;
摘要
The expected advent of the Internet of Things (IoT) has triggered a large demand of embedded devices, which envisions the autonomous interaction of sensors and actuators while offering all sort of smart services. However, these IoT devices are limited in computation, storage, and network capacity, which makes them easy to hack and compromise. To achieve secure development of IoT, it is necessary to engineer scalable security solutions optimized for the IoT ecosystem. To this end, Software Defined Networking (SDN) is a promising paradigm that serves as a pillar in the fifth generation of mobile systems (5G) that could help to detect and mitigate Denial of Service (DoS) and Distributed DoS (DDoS) threats. In this work, we propose to experimentally evaluate an entropy-based solution to detect and mitigate DoS and DDoS attacks in IoT scenarios using a stateful SDN data plane. The obtained results demonstrate for the first time the effectiveness of this technique targeting real IoT data traffic.
引用
收藏
页数:18
相关论文
共 50 条
  • [21] DDoS-FOCUS: A Distributed DoS Attacks Mitigation using Deep Learning Approach for a Secure IoT Network
    Al-khafajiy, Mohammed
    Al-Tameemi, Ghaith
    Baker, Thar
    [J]. 2023 IEEE INTERNATIONAL CONFERENCE ON EDGE COMPUTING AND COMMUNICATIONS, EDGE, 2023, : 393 - 399
  • [22] Traffic Monitoring and DDoS Detection using Stateful SDN
    Rebecchi, Filippo
    Boite, Julien
    Nardin, Pierre-Alexis
    Bouet, Mathieu
    Conan, Vania
    [J]. 2017 IEEE CONFERENCE ON NETWORK SOFTWARIZATION (IEEE NETSOFT), 2017,
  • [23] SDN-Guard: DoS Attacks Mitigation in SDN Networks
    Dridi, Lobna
    Zhani, Mohamed Faten
    [J]. 2016 5TH IEEE INTERNATIONAL CONFERENCE ON CLOUD NETWORKING (IEEE CLOUDNET), 2016, : 212 - 217
  • [24] Efficient DDoS attacks mitigation for stateful forwarding in Internet of Things
    Liu, Gang
    Quan, Wei
    Cheng, Nan
    Zhang, Hongke
    Yu, Shui
    [J]. JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2019, 130 : 1 - 13
  • [25] An RBF-PSO Based Approach for Early Detection of DDoS Attacks in SDN
    Dayal, Neelam
    Srivastava, Shashank
    [J]. 2018 10TH INTERNATIONAL CONFERENCE ON COMMUNICATION SYSTEMS & NETWORKS (COMSNETS), 2018, : 17 - 24
  • [26] BSD-Guard: A Collaborative Blockchain-Based Approach for Detection and Mitigation of SDN-Targeted DDoS Attacks
    Jiang, Shanqing
    Yang, Lin
    Gao, Xianming
    Zhou, Yuyang
    Feng, Tao
    Song, Yanbo
    Liu, Kexian
    Cheng, Guang
    [J]. SECURITY AND COMMUNICATION NETWORKS, 2022, 2022
  • [27] SDN-Defend: A Lightweight Online Attack Detection and Mitigation System for DDoS Attacks in SDN
    Wang, Jin
    Wang, Liping
    [J]. SENSORS, 2022, 22 (21)
  • [28] A Framework for Mitigating DDoS and DOS Attacks in IoT Environment Using Hybrid Approach
    Ghali, Abdulrahman Aminu
    Ahmad, Rohiza
    Alhussian, Hitham
    [J]. ELECTRONICS, 2021, 10 (11)
  • [29] Timely Detection and Mitigation of Stealthy DDoS Attacks Via IoT Networks
    Doshi, Keval
    Yilmaz, Yasin
    Uludag, Suleyman
    [J]. IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2021, 18 (05) : 2164 - 2176
  • [30] Detecting DDoS Attacks in IoT-Based Networks Using Matrix Profile
    Alzahrani, Mohammed Ali
    Alzahrani, Ali M.
    Siddiqui, Muhammad Shoaib
    [J]. APPLIED SCIENCES-BASEL, 2022, 12 (16):