Scalable and secure SDN based ethernet architecture by suppressing broadcast traffic

被引:3
|
作者
Munther, Munther Numan [1 ]
Hashim, Fazirulhisyam [1 ]
Latiff, Nurul Adilah Abdul [2 ]
Alezabi, Kamal Ali [3 ]
Liew, Jiun Terng [1 ]
机构
[1] Univ Putra Malaysia, Fac Engn, Dept Comp & Commun Syst Engn, Bangi, Selangor, Malaysia
[2] Univ Malaysia Terengganu, Sch Ocean Engn, Terengganu, Malaysia
[3] UCSI Univ, Inst Comp Sci & Digital Innovat ICSDI, Kuala Lumpur, Malaysia
关键词
Software-defined network (SDN); Ethernet scalability; Address Resolution Protocol (ARP); Dynamic host configuration protocol (DHCP); ARP storm; Spoofing attack; FLOODLESS;
D O I
10.1016/j.eij.2021.08.001
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Ethernet is one of the widespread protocols residing in the second layer of the seven-layers Open Systems Interconnection (OSI) model. Ethernet offers various advantages which enable its widespread use in all types of network topology and becomes an essential part of computer and network architecture. Despite its features, Ethernet suffers from scalability issues where the increasing number of hosts in a single broadcast domain will significantly expand the broadcast traffic in the network. Since the emergence of software-defined networking (SDN), researchers exploited various attractive features of SDN to suppress the broadcast traffic. Although capable in addressing the scalability issue of Ethernet, the existing SDN based solutions are lacking of security mechanism, which may expose the network to various ARP based attacks. Owing to this issue, this paper proposes a floodless and secure mechanism to suppress broadcast traffic. In general, the proposed solution utilizes SDN architecture and accommodates a multistage security algorithm. The multistage security algorithm consists of three stages; each stage incorporates specific analysis to identify the packet status or behavior, and react accordingly based on its status. To demonstrate the efficiency of the proposed solution, several ARP based attack scenarios are generated and evaluated using Mininet emulator. The performance evaluation indicates that the true positive ratio for attack detection in the proposed solution is 57.14% for the first stage, 66.66% for the second stage, and in some cases may achieve 100% for the final stage. (c) 2022 Published by Elsevier B.V. on behalf of Faculty of Computers and Information, Cairo University. This is an open access article under the CC BY-NC-ND license (http://creativecommons.org/licenses/by-ncnd/4.0/).
引用
收藏
页码:113 / 126
页数:14
相关论文
共 50 条
  • [1] Scalable Ethernet Architecture using SDN by Suppressing Broadcast Traffic
    Jehan, Naseela
    Haneef, Aneesh M.
    [J]. 2015 FIFTH INTERNATIONAL CONFERENCE ON ADVANCES IN COMPUTING AND COMMUNICATIONS (ICACC), 2015, : 24 - 27
  • [2] EtherProxy: Scaling Ethernet By Suppressing Broadcast Traffic
    Elmeleegy, Khaled
    Cox, Alan L.
    [J]. IEEE INFOCOM 2009 - IEEE CONFERENCE ON COMPUTER COMMUNICATIONS, VOLS 1-5, 2009, : 1584 - 1592
  • [3] Scalable Architecture for SDN Traffic Classification
    Hayes, Matthew
    Ng, Bryan
    Pekar, Adrian
    Seah, Winston K. G.
    [J]. IEEE SYSTEMS JOURNAL, 2018, 12 (04): : 3203 - 3214
  • [4] An Adaptive Broadcast and Multicast Traffic Cutting Framework to Improve Ethernet Efficiency by SDN
    Wang, You-Chiun
    Hu, Han
    [J]. JOURNAL OF INFORMATION SCIENCE AND ENGINEERING, 2019, 35 (02) : 375 - 392
  • [5] A Secure Network Coding Based on Broadcast Encryption in SDN
    Chen, Yue
    Jia, Hongyong
    Huang, Kaixiang
    Lan, Julong
    Yan, Xincheng
    [J]. MATHEMATICAL PROBLEMS IN ENGINEERING, 2016, 2016
  • [6] SDN-Based Secure Architecture for IoT
    Mishra, Shailendra
    [J]. INTERNATIONAL JOURNAL OF KNOWLEDGE AND SYSTEMS SCIENCE, 2020, 11 (04) : 1 - 16
  • [7] Original secure architecture for IoT based on SDN
    Flauzac, Olivier
    Gonzalez, Carlos
    Nolot, Florent
    [J]. 2015 INTERNATIONAL CONFERENCE ON PROTOCOL ENGINEERING (ICPE) AND INTERNATIONAL CONFERENCE ON NEW TECHNOLOGIES OF DISTRIBUTED SYSTEMS (NTDS), 2015,
  • [8] Towards A Secure SDN Architecture
    Raghunath, Karthik
    Krishnan, Prabhakar
    [J]. 2018 9TH INTERNATIONAL CONFERENCE ON COMPUTING, COMMUNICATION AND NETWORKING TECHNOLOGIES (ICCCNT), 2018,
  • [9] MOTIM - A scalable architecture for Ethernet switches
    Bastos, Erico
    Carara, Everton
    Pigatto, Daniel
    Calazans, Ney
    Moraes, Fernando
    [J]. IEEE COMPUTER SOCIETY ANNUAL SYMPOSIUM ON VLSI, PROCEEDINGS: EMERGING VLSI TECHNOLOGIES AND ARCHITECTURES, 2007, : 451 - +
  • [10] Ethernet Fabric Routing (UETS/EFR) -: A hierarchical, scalable and secure ultrahigh speed switching architecture
    Barroso, Jose Morales
    Fernandez, Guillermo Ibanez
    [J]. 25TH IEEE INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATIONS, VOLS 1-7, PROCEEDINGS IEEE INFOCOM 2006, 2006, : 3037 - 3041