Mitigating DDoS Attacks in SDN-Based IoT Networks Leveraging Secure Control and Data Plane Algorithm

被引:21
|
作者
Wang, Song [1 ]
Gomez, Karina [1 ]
Sithamparanathan, Kandeepan [1 ]
Asghar, Muhammad Rizwan [2 ]
Russello, Giovanni [2 ]
Zanna, Paul [3 ]
机构
[1] RMIT Univ, Sch Engn, Melbourne, Vic 3000, Australia
[2] Univ Auckland, Cyber Secur Foundry, Auckland 1142, New Zealand
[3] Northbound Networks, Hoppers Crossing, Vic 3029, Australia
来源
APPLIED SCIENCES-BASEL | 2021年 / 11卷 / 03期
关键词
DDoS; SDN; IoT; OpenFlow; Zodiac; security; Packet_In message; TCP; UDP; INTERNET; 5G;
D O I
10.3390/app11030929
中图分类号
O6 [化学];
学科分类号
0703 ;
摘要
Software-Defined Networking (SDN) and Internet of Things (IoT) are the trends of network evolution. SDN mainly focuses on the upper level control and management of networks, while IoT aims to bring devices together to enable sharing and monitoring of real-time behaviours through network connectivity. On the one hand, IoT enables us to gather status of devices and networks and to control them remotely. On the other hand, the rapidly growing number of devices challenges the management at the access and backbone layer and raises security concerns of network attacks, such as Distributed Denial of Service (DDoS). The combination of SDN and IoT leads to a promising approach that could alleviate the management issue. Indeed, the flexibility and programmability of SDN could help in simplifying the network setup. However, there is a need to make a security enhancement in the SDN-based IoT network for mitigating attacks involving IoT devices. In this article, we discuss and analyse state-of-the-art DDoS attacks under SDN-based IoT scenarios. Furthermore, we verify our SDN sEcure COntrol and Data plane (SECOD) algorithm to resist DDoS attacks on the real SDN-based IoT testbed. Our results demonstrate that DDoS attacks in the SDN-based IoT network are easier to detect than in the traditional network due to IoT traffic predictability. We observed that random traffic (UDP or TCP) is more affected during DDoS attacks. Our results also show that the probability of a controller becoming halt is 10%, while the probability of a switch getting unresponsive is 40%.
引用
收藏
页码:1 / 27
页数:27
相关论文
共 50 条
  • [1] Detecting and Preventing DDoS Attacks in SDN-Based Data Center Networks
    Lin, Po-Ching
    Hsu, Yu-Ting
    Hwang, Ren-Hung
    [J]. CLOUD COMPUTING AND SECURITY, PT II, 2017, 10603 : 50 - 61
  • [2] Using MTD and SDN-based Honeypots to Defend DDoS Attacks in IoT
    Luo, Xupeng
    Yan, Qiao
    Wang, Mingde
    Huang, Wenyao
    [J]. 2019 COMPUTING, COMMUNICATIONS AND IOT APPLICATIONS (COMCOMAP), 2019, : 392 - 395
  • [3] Defending SDN-based IoT Networks Against DDoS Attacks Using Markov Decision Process
    Zheng, Jianjun
    Namin, Akbar Siami
    [J]. 2018 IEEE INTERNATIONAL CONFERENCE ON BIG DATA (BIG DATA), 2018, : 4589 - 4592
  • [4] NGS: Mitigating DDoS Attacks using SDN-based Network Gate Shield
    Dalati, Mohamad Suhel
    Meng, Weizhi
    Chiu, Wei-Yang
    [J]. 2021 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2021,
  • [5] Secure and Reliable Data Transmission in SDN-based Backend Networks of Industrial IoT
    Li, Tao
    Hofmann, Christoph
    Franz, Elke
    [J]. PROCEEDINGS OF THE 2020 IEEE 45TH CONFERENCE ON LOCAL COMPUTER NETWORKS (LCN 2020), 2020, : 365 - 368
  • [6] SDN-Based Secure Architecture for IoT
    Mishra, Shailendra
    [J]. INTERNATIONAL JOURNAL OF KNOWLEDGE AND SYSTEMS SCIENCE, 2020, 11 (04) : 1 - 16
  • [7] SDN-based detection and mitigation of DDoS attacks on smart homes
    Garba, Usman Haruna
    Toosi, Adel N.
    Pasha, Muhammad Fermi
    Khan, Suleman
    [J]. COMPUTER COMMUNICATIONS, 2024, 221 : 29 - 41
  • [8] A DDoS attacks traceback scheme for SDN-based smart city
    Chen, Wen
    Xiao, Suchao
    Liu, Leijie
    Jiang, Xueqin
    Tang, Zhangbin
    [J]. COMPUTERS & ELECTRICAL ENGINEERING, 2020, 81
  • [9] An SDN-based Approach For Defending Against Reflective DDoS Attacks
    Lukaseder, Thomas
    StOlzle, Kevin
    Kleber, Stephan
    Erb, Benjamin
    Kargl, Frank
    [J]. PROCEEDINGS OF THE 2018 IEEE 43RD CONFERENCE ON LOCAL COMPUTER NETWORKS (LCN), 2018, : 299 - 302
  • [10] SECOD: SDN sEcure COntrol and Data Plane Algorithm for Detecting and Defending against DoS Attacks
    Wang, Song
    Chandrasekharan, Sathyanarayanan
    Gomez, Karina
    Kandeepan, Sithamparanathan
    Al-Hourani, Akram
    Asghar, Muhammad Rizwan
    Russello, Giovanni
    Zanna, Paul
    [J]. NOMS 2018 - 2018 IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM, 2018,