FuzzyGuard: A DDoS attack prevention extension in software-defined wireless sensor networks

被引:1
|
作者
Huang, Meigen [1 ]
Yu, Bin [1 ]
机构
[1] Zhengzhou Informat Sci & Technol Inst, Dept Comp Sci & Informat Engn, Zhengzhou 450001, Henan, Peoples R China
基金
中国国家自然科学基金;
关键词
Distributed denial of service; control plane saturation attack; wireless sensor networks; software-defined networking; fuzzy inference;
D O I
10.3837/tiis.2019.07.019
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Software defined networking brings unique security risks such as control plane saturation attack while enhancing the performance of wireless sensor networks. The attack is a new type of distributed denial of service (DDoS) attack, which is easy to launch. However, it is difficult to detect and hard to defend. In response to this, the attack threat model is discussed firstly, and then a DDoS attack prevention extension, called FuzzyGuard, is proposed. In FuzzyGuard, a control network with both the protection of data flow and the convergence of attack flow is constructed in the data plane by using the idea of independent routing control flow. Then, the attack detection is implemented by fuzzy inference method to output the current security state of the network. Different probabilistic suppression modes are adopted subsequently to deal with the attack flow to cost-effectively reduce the impact of the attack on the network. The prototype is implemented on SDN-WISE and the simulation experiment is carried out. The evaluation results show that FuzzyGuard could effectively protect the normal forwarding of data flow in the attacked state and has a good defensive effect on the control plane saturation attack with lower resource requirements.
引用
收藏
页码:3671 / 3689
页数:19
相关论文
共 50 条
  • [41] Node Scheduling for Localization in Heterogeneous Software-Defined Wireless Sensor Networks
    Zhu, Yaping
    Yan, Feng
    Xia, Weiwei
    Shen, Fei
    Xing, Song
    Wu, Yi
    Shen, Lianfeng
    [J]. AD HOC NETWORKS, ADHOCNETS 2018, 2019, 258 : 154 - 164
  • [42] Software-Defined Wireless Sensor Networks and Internet of Things Standardization Synergism
    de Oliveira, Bruno Trevizan
    Afonso Alves, Renan Cerqueira
    Margi, Cintia Borges
    [J]. 2015 IEEE CONFERENCE ON STANDARDS FOR COMMUNICATIONS AND NETWORKING (CSCN), 2015, : 60 - 65
  • [43] A Survey on Software-Defined Wireless Sensor Networks: Challenges and Design Requirements
    Kobo, Hlabishi I.
    Abu-Mahfouz, Adnan M.
    Hancke, Gerhard P.
    [J]. IEEE ACCESS, 2017, 5 : 1872 - 1899
  • [44] Denial of Service Attacks Detection in Software-Defined Wireless Sensor Networks
    Nunez Segura, Gustavo A.
    Skaperas, Sotiris
    Chorti, Arsenia
    Mamatas, Lefteris
    Margi, Cintia Borges
    [J]. 2020 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS WORKSHOPS (ICC WORKSHOPS), 2020,
  • [45] TinySDN: Enabling Multiple Controllers for Software-Defined Wireless Sensor Networks
    de Oliveira, Bruno Trevizan
    Margi, Cintia Borges
    Gabriel, Lucas Batista
    [J]. 2014 IEEE LATIN-AMERICA CONFERENCE ON COMMUNICATIONS (LATINCOM), 2014,
  • [46] DDoS attack protection in the era of cloud computing and Software-Defined Networking
    Wang, Bing
    Zheng, Yao
    Lou, Wenjing
    Hou, Y. Thomas
    [J]. COMPUTER NETWORKS, 2015, 81 : 308 - 319
  • [47] Securing Software-Defined Vehicular Network Architecture against DDoS attack
    Amari, Houda
    Louati, Wassef
    Khoukhi, Lyes
    Belguith, Lamia Hadrich
    [J]. PROCEEDINGS OF THE IEEE 46TH CONFERENCE ON LOCAL COMPUTER NETWORKS (LCN 2021), 2021, : 653 - 656
  • [48] Intrusion Prevention with Attack Traceback and Software-defined Control Plane for Campus Networks
    Guo, Guangfeng
    Zhang, Junxing
    Ma, Zhanfei
    [J]. COMPUTER SCIENCE AND INFORMATION SYSTEMS, 2021, 18 (03) : 867 - 891
  • [49] A DDoS Attack Detection and Mitigation With Software-Defined Internet of Things Framework
    Yin, Da
    Zhang, Lianming
    Yang, Kun
    [J]. IEEE ACCESS, 2018, 6 : 24694 - 24705
  • [50] DDoS Attack Protection in the Era of Cloud Computing and Software-Defined Networking
    Wang, Bing
    Zheng, Yao
    Lou, Wenjing
    Hou, Y. Thomas
    [J]. 2014 IEEE 22ND INTERNATIONAL CONFERENCE ON NETWORK PROTOCOLS (ICNP), 2014, : 624 - 629