Detection and Mitigation of DoS and DDoS Attacks in IoT-Based Stateful SDN: An Experimental Approach

被引:76
|
作者
Galeano-Brajones, Jesus [1 ]
Carmona-Murillo, Javier [1 ]
Valenzuela-Valdes, Juan F. [2 ]
Luna-Valero, Francisco [3 ,4 ]
机构
[1] Univ Extremadura, Dept Comp & Telemat Engn, Merida 06800, Spain
[2] Univ Granada, Dept Signal Theory Telemat & Commun, E-18071 Granada, Spain
[3] Univ Malaga, ITIS Software, E-29071 Malaga, Spain
[4] Univ Malaga, Dept Languages & Comp Sci, E-29071 Malaga, Spain
关键词
stateful SDN; DoS; DDoS; entropy; Internet of Things; experimental evaluation; INTERNET; SECURITY; ENTROPY; NFV;
D O I
10.3390/s20030816
中图分类号
O65 [分析化学];
学科分类号
070302 ; 081704 ;
摘要
The expected advent of the Internet of Things (IoT) has triggered a large demand of embedded devices, which envisions the autonomous interaction of sensors and actuators while offering all sort of smart services. However, these IoT devices are limited in computation, storage, and network capacity, which makes them easy to hack and compromise. To achieve secure development of IoT, it is necessary to engineer scalable security solutions optimized for the IoT ecosystem. To this end, Software Defined Networking (SDN) is a promising paradigm that serves as a pillar in the fifth generation of mobile systems (5G) that could help to detect and mitigate Denial of Service (DoS) and Distributed DoS (DDoS) threats. In this work, we propose to experimentally evaluate an entropy-based solution to detect and mitigate DoS and DDoS attacks in IoT scenarios using a stateful SDN data plane. The obtained results demonstrate for the first time the effectiveness of this technique targeting real IoT data traffic.
引用
收藏
页数:18
相关论文
共 50 条
  • [31] An IoT-Based Intrusion Detection System Approach for TCP SYN Attacks
    Berguiga, Abdelwahed
    Harchay, Ahlem
    [J]. CMC-COMPUTERS MATERIALS & CONTINUA, 2022, 71 (02): : 3839 - 3851
  • [32] Detection and Mitigation of IoT-Based Attacks Using SNMP and Moving Target Defense Techniques
    Gayathri, Rajakumaran
    Usharani, Shola
    Mahdal, Miroslav
    Vezhavendhan, Rajasekharan
    Vincent, Rajiv
    Rajesh, Murugesan
    Elangovan, Muniyandy
    [J]. SENSORS, 2023, 23 (03)
  • [33] DHCP DoS and starvation attacks on SDN controllers and their mitigation
    Ishtiaq, Hafiz Usama
    Bhutta, Areeb Ahmed
    Mian, Adnan Noor
    [J]. JOURNAL OF COMPUTER VIROLOGY AND HACKING TECHNIQUES, 2024, 20 (01) : 15 - 25
  • [34] DHCP DoS and starvation attacks on SDN controllers and their mitigation
    Hafiz Usama Ishtiaq
    Areeb Ahmed Bhutta
    Adnan Noor Mian
    [J]. Journal of Computer Virology and Hacking Techniques, 2024, 20 : 15 - 25
  • [35] A DDoS Detection and Mitigation System Framework Based on Spark and SDN
    Yan, Qiao
    Huang, Wenyao
    [J]. SMART COMPUTING AND COMMUNICATION, SMARTCOM 2016, 2017, 10135 : 350 - 358
  • [36] Using MTD and SDN-based Honeypots to Defend DDoS Attacks in IoT
    Luo, Xupeng
    Yan, Qiao
    Wang, Mingde
    Huang, Wenyao
    [J]. 2019 COMPUTING, COMMUNICATIONS AND IOT APPLICATIONS (COMCOMAP), 2019, : 392 - 395
  • [37] Time-based DDoS Detection and Mitigation for SDN Controller
    Dharma, I. Gde N.
    Muthohar, M. Fiqri
    Prayuda, Alvin J. D.
    Priagung, K.
    Choi, Deokjai
    [J]. 2015 17TH ASIA-PACIFIC NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM APNOMS, 2015, : 550 - 553
  • [38] SDN-Assisted Network-Based Mitigation of Slow DDoS Attacks
    Lukaseder, Thomas
    Maile, Lisa
    Erb, Benjamin
    Kargl, Frank
    [J]. SECURITY AND PRIVACY IN COMMUNICATION NETWORKS, SECURECOMM 2018, PT II, 2018, 255 : 102 - 121
  • [39] Detection and mitigation of DDoS attacks in SDN: A comprehensive review, research challenges and future directions
    Singh, Jagdeep
    Behal, Sunny
    [J]. COMPUTER SCIENCE REVIEW, 2020, 37
  • [40] One-Dimensional Convolutional Neural Network for Detection and Mitigation of DDoS Attacks in SDN
    Alshra'a, Abdullah
    Jochen, Seitz
    [J]. MACHINE LEARNING FOR NETWORKING, MLN 2021, 2022, 13175 : 11 - 28