Reactive security for SDN/NFV-enabled industrial networks leveraging service function chaining

被引:13
|
作者
Petroulakis, Nikolaos E. [1 ,2 ]
Fysarakis, Konstantinos [1 ]
Askoxylakis, Ioannis [1 ]
Spanoudakis, George [2 ]
机构
[1] Fdn Res & Technol Hellas, Iraklion 70013, Greece
[2] City Univ London, London EC1V 0HB, England
基金
欧盟地平线“2020”;
关键词
INTERNET;
D O I
10.1002/ett.3269
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
The innovative application of fifth-generation core technologies, ie, software-defined networking (SDN) and network function virtualization, can help reduce capital and operational expenditures in industrial networks. Nevertheless, SDN expands the attack surface of the communication infrastructure, thus necessitating the introduction of additional security mechanisms. These major changes could not leave the industrial environment unaffected, with smart industrial deployments gradually becoming a reality, a trend that is often referred to as the Fourth Industrial Revolution or Industry 4.0. A wind park is a good example of an industrial application relying on a network with strict performance, security, and reliability requirements and was chosen as a representative example of industrial systems. This work highlights the benefit of leveraging the flexibility of SDN/network function virtualization-enabled networks to deploy enhanced reactive security mechanisms for the protection of the industrial network via the use of service function chaining. Moreover, the implementation of a proof-of-concept reactive security framework for an industrial-grade wind park network is presented, along with a performance evaluation of the proposed approach. The framework is equipped with SDN and supervisory control and data acquisition honeypots, modeled on and deployable to the wind park, allowing continuous monitoring of the industrial network and detailed analysis of potential attacks, thus isolating attackers and enabling the assessment of their level of sophistication. Moreover, the applicability of the proposed solutions is assessed in the context of the specific industrial application based on the analysis of the network characteristics and requirements of an actual operating wind park.
引用
收藏
页数:18
相关论文
共 50 条
  • [1] A Dynamic Composition Mechanism of Security Service Chaining Oriented to SDN/NFV-Enabled Networks
    Liu, Yicen
    Lu, Yu
    Qiao, Wenxin
    Chen, Xingkai
    [J]. IEEE ACCESS, 2018, 6 : 53918 - 53929
  • [2] Virtual Network Function Selection and Chaining based on Deep Learning in SDN and NFV-Enabled Networks
    Pei, Jianing
    Hong, Peilin
    Li, Defang
    [J]. 2018 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS WORKSHOPS (ICC WORKSHOPS), 2018,
  • [3] On Dynamic Mapping and Scheduling of Service Function Chains in SDN/NFV-Enabled Networks
    Li, Junling
    Shi, Weisen
    Yang, Peng
    Shen, Xuemin
    [J]. 2019 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2019,
  • [4] Reliability-aware service chaining mapping in NFV-enabled networks
    Liu, Yicen
    Lu, Yu
    Qiao, Wenxin
    Chen, Xingkai
    [J]. ETRI JOURNAL, 2019, 41 (02) : 207 - 223
  • [5] Efficient Algorithms for Service Chaining in NFV-Enabled Satellite Edge Networks
    Xia, Qiufen
    Wang, Guijie
    Xu, Zichuan
    Liang, Weifa
    Xu, Zhou
    [J]. IEEE TRANSACTIONS ON MOBILE COMPUTING, 2024, 23 (05) : 5677 - 5694
  • [6] Distributed service function chaining in NFV-enabled networks: A game-theoretic learning approach
    Alikhani, Mahsa
    Hakami, Vesal
    Sheikhi, Marzieh
    [J]. JOURNAL OF COMPUTATIONAL SCIENCE, 2024, 82
  • [7] Towards SDN/NFV-enabled satellite networks
    Gardikis, Georgios
    Koumaras, Harilaos
    Sakkas, Chris
    Koumaras, Vaios
    [J]. TELECOMMUNICATION SYSTEMS, 2017, 66 (04) : 615 - 628
  • [8] Towards SDN/NFV-enabled satellite networks
    Georgios Gardikis
    Harilaos Koumaras
    Chris Sakkas
    Vaios Koumaras
    [J]. Telecommunication Systems, 2017, 66 : 615 - 628
  • [9] Multicast Service Function Chain Orchestration in SDN/NFV-Enabled Networks: Embedding, Readjustment, and Expanding
    Li, Hang
    Wang, Luhan
    Zhu, Zhenghe
    Chen, Yawen
    Lu, Zhaoming
    Wen, Xiangming
    [J]. IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2023, 20 (04): : 4634 - 4651
  • [10] Resource Aware Routing for Service Function Chains in SDN and NFV-Enabled Network
    Pei, Jianing
    Hong, Peilin
    Xue, Kaiping
    Li, Defang
    [J]. IEEE TRANSACTIONS ON SERVICES COMPUTING, 2021, 14 (04) : 985 - 997