Defending Against New-Flow Attack in SDN-Based Internet of Things

被引:41
|
作者
Xu, Tong [1 ]
Gao, Deyun [1 ]
Dong, Ping [1 ]
Zhang, Hongke [1 ]
Foh, Chuan Heng [2 ]
Chao, Han-Chieh [3 ]
机构
[1] Beijing Jiaotong Univ, Sch Elect & Informat Engn, Natl Engn Lab Next Generat Internet Interconnect, Beijing 100044, Peoples R China
[2] Univ Surrey, Inst Commun Syst, Dept Elect & Elect Engn, IC 5G, Surrey GU1 2UX, England
[3] Natl Dong Hwa Univ, Shoufeng Township 974, Taiwan
来源
IEEE ACCESS | 2017年 / 5卷
关键词
Internet of Things; software-defined networking; OpenFlow; communication system security; new-flow attack; SOFTWARE-DEFINED NETWORKING;
D O I
10.1109/ACCESS.2017.2666270
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Recently, the Internet of Things (IoT) is attracting significant attention from both academia and industry. To connect the huge amount of IoT devices effectively, software-defined networking (SDN) is considered as a promising way because of its centralized network management and programmable routing logic. However, due to the limited resources in both the data plane and the control plane, SDN is vulnerable to the new-flow attack, which can disable the SDN-based IoT by exhausting the switches or the controller. Therefore, in this paper, we propose a smart security mechanism (SSM) to defend against the new-flow attack. The SSM uses the standard southbound and northbound interfaces of SDN, and it includes a low-cost method that monitors the new-flow attack by reusing the asynchronous messages on the control link. The monitor method can differentiate the new-flow attack from the normal flow burst by checking the hit rate of the flow entries. Based on the monitoring result, the SSM uses a dynamic access control method to mitigate the new-flow attack by perceiving the behavior of the security middleware in the IoT. The dynamic access control method can intercept the attack flows at their access switch. Extensive simulations and testbed-based experiments are conducted and the corresponding results verify the feasibility of our claims.
引用
收藏
页码:3431 / 3443
页数:13
相关论文
共 50 条
  • [21] Defending Internet of Things against Exploits
    Teixeira, F. A.
    Machado, G. V.
    Fonseca, P. M.
    Pereira, F. M. Q.
    Wong, H. C.
    Nogueira, J. M. S.
    Oliveira, L. B.
    IEEE LATIN AMERICA TRANSACTIONS, 2015, 13 (04) : 1112 - 1119
  • [22] SDN-Based Link Recovery Scheme for Large-Scale Internet of Things
    Ahmed, Nurzaman
    Roy, Arijit
    Mondal, Ayan
    Misra, Sudip
    2021 IEEE 22ND INTERNATIONAL CONFERENCE ON HIGH PERFORMANCE SWITCHING AND ROUTING (IEEE HPSR), 2021,
  • [23] Toward an SDN-Based Web Application Firewall: Defending against SQL Injection Attacks
    Alotaibi, Fahad M.
    Vassilakis, Vassilios G.
    FUTURE INTERNET, 2023, 15 (05)
  • [24] SDN-based hybrid honeypot for attack capture
    Wang, He
    Wu, Bin
    PROCEEDINGS OF 2019 IEEE 3RD INFORMATION TECHNOLOGY, NETWORKING, ELECTRONIC AND AUTOMATION CONTROL CONFERENCE (ITNEC 2019), 2019, : 1602 - 1606
  • [25] Routing Optimization For Cloud Services in SDN-based Internet of Things With TCAM Capacity Constraint
    Xu, Shizhong
    Wang, Xiong
    Yang, Guangxu
    Ren, Jing
    Wang, Sheng
    JOURNAL OF COMMUNICATIONS AND NETWORKS, 2020, 22 (02) : 145 - 158
  • [26] SDM4IIoT: An SDN-Based Multicast Algorithm for Industrial Internet of Things
    Li, Hequn
    Lu, Jiaxi
    Wang, Jinfa
    Zhao, Hai
    Xu, Jiuqiang
    Chen, Xingchi
    IEICE TRANSACTIONS ON COMMUNICATIONS, 2022, E105B (05) : 545 - 556
  • [27] A proactive defense method against eavesdropping attack in SDN-based storage environment
    Liu, Yuming
    Wang, Yong
    Feng, Hao
    CYBERSECURITY, 2024, 7 (01):
  • [28] Optimal Placement of Cloudlets for Access Delay Minimization in SDN-Based Internet of Things Networks
    Zhao, Lei
    Sun, Wen
    Shi, Yongpeng
    Liu, Jiajia
    IEEE INTERNET OF THINGS JOURNAL, 2018, 5 (02): : 1334 - 1344
  • [29] An adaptive data coding scheme for energy consumption reduction in SDN-based Internet of Things
    Salehi, Shahab
    Farbeh, Hamed
    Rokhsari, Alireza
    COMPUTER NETWORKS, 2023, 221
  • [30] Defending SDN-based IoT Networks Against DDoS Attacks Using Markov Decision Process
    Zheng, Jianjun
    Namin, Akbar Siami
    2018 IEEE INTERNATIONAL CONFERENCE ON BIG DATA (BIG DATA), 2018, : 4589 - 4592