Reactive security for SDN/NFV-enabled industrial networks leveraging service function chaining

被引:13
|
作者
Petroulakis, Nikolaos E. [1 ,2 ]
Fysarakis, Konstantinos [1 ]
Askoxylakis, Ioannis [1 ]
Spanoudakis, George [2 ]
机构
[1] Fdn Res & Technol Hellas, Iraklion 70013, Greece
[2] City Univ London, London EC1V 0HB, England
基金
欧盟地平线“2020”;
关键词
INTERNET;
D O I
10.1002/ett.3269
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
The innovative application of fifth-generation core technologies, ie, software-defined networking (SDN) and network function virtualization, can help reduce capital and operational expenditures in industrial networks. Nevertheless, SDN expands the attack surface of the communication infrastructure, thus necessitating the introduction of additional security mechanisms. These major changes could not leave the industrial environment unaffected, with smart industrial deployments gradually becoming a reality, a trend that is often referred to as the Fourth Industrial Revolution or Industry 4.0. A wind park is a good example of an industrial application relying on a network with strict performance, security, and reliability requirements and was chosen as a representative example of industrial systems. This work highlights the benefit of leveraging the flexibility of SDN/network function virtualization-enabled networks to deploy enhanced reactive security mechanisms for the protection of the industrial network via the use of service function chaining. Moreover, the implementation of a proof-of-concept reactive security framework for an industrial-grade wind park network is presented, along with a performance evaluation of the proposed approach. The framework is equipped with SDN and supervisory control and data acquisition honeypots, modeled on and deployable to the wind park, allowing continuous monitoring of the industrial network and detailed analysis of potential attacks, thus isolating attackers and enabling the assessment of their level of sophistication. Moreover, the applicability of the proposed solutions is assessed in the context of the specific industrial application based on the analysis of the network characteristics and requirements of an actual operating wind park.
引用
收藏
页数:18
相关论文
共 50 条
  • [31] Cost-aware Service Function Chaining With Reliability Guarantees in NFV-enabled Inter-DC Network
    Zhong, Xuxia
    Wang, Ying
    Qiu, Xuesong
    [J]. 2019 IFIP/IEEE SYMPOSIUM ON INTEGRATED NETWORK AND SERVICE MANAGEMENT (IM), 2019, : 304 - 311
  • [32] Survivable Service Function Chain Mapping in NFV-Enabled 5G Networks
    Hu, Yue
    Guo, Yongan
    [J]. PROCEEDINGS OF THE 2021 IEEE 7TH INTERNATIONAL CONFERENCE ON NETWORK SOFTWARIZATION (NETSOFT 2021): ACCELERATING NETWORK SOFTWARIZATION IN THE COGNITIVE AGE, 2021, : 375 - 380
  • [33] Dynamic VNF Placement for Mapping Service Function Chain Requests in NFV-enabled Networks
    Yue, Yi
    Cheng, Bo
    Liu, Xuan
    Wang, Meng
    Li, Biyi
    [J]. WWW'20: COMPANION PROCEEDINGS OF THE WEB CONFERENCE 2020, 2020, : 44 - 45
  • [34] RQAP: Resource and QoS Aware Placement of Service Function Chains in NFV-Enabled Networks
    Huang, Haojun
    Tian, Jialin
    Yin, Hao
    Min, Geyong
    Wu, Dapeng
    Miao, Wang
    [J]. IEEE TRANSACTIONS ON SERVICES COMPUTING, 2023, 16 (06) : 4526 - 4539
  • [35] Virtual IoT HoneyNets to Mitigate Cyberattacks in SDN/NFV-Enabled IoT Networks
    Zarca, Alejandro Molina
    Bernabe, Jorge Bernal
    Skarmeta, Antonio
    Alcaraz Calero, Jose M.
    [J]. IEEE JOURNAL ON SELECTED AREAS IN COMMUNICATIONS, 2020, 38 (06) : 1262 - 1277
  • [36] Improving dynamic service function chaining classification in NFV/SDN networks through the offloading concept
    Polverini, Marco
    Galan-Jimenez, Jaime
    Lavacca, Francesco G.
    Cianfrani, Antonio
    Eramo, Vincenzo
    [J]. COMPUTER NETWORKS, 2020, 182
  • [37] Enabling autonomic provisioning in SDN cloud networks with NFV service chaining
    Cannistra, Robert
    Carle, Benjamin
    Johnson, Matt
    Kapadia, Junaid
    Meath, Zach
    Miller, Mary
    Young, Devin
    DeCusatis, Casimer
    Bundy, Todd
    Zussman, Gil
    Bergman, Keren
    Carranza, Aparicio
    Sher-DeCusatis, Carolyn
    Pletch, Andrew
    Ransom, Raymond
    [J]. 2014 OPTICAL FIBER COMMUNICATIONS CONFERENCE AND EXHIBITION (OFC), 2014,
  • [38] Modeling and Performance Analysis for Service Function Chaining in the SDN/NFV Architecture
    Duan, Qiang
    [J]. 2018 4TH IEEE CONFERENCE ON NETWORK SOFTWARIZATION AND WORKSHOPS (NETSOFT), 2018, : 476 - 481
  • [39] Leveraging LTE Security with SDN and NFV
    Liyanage, Madhusanka
    Ahmad, Ljaz
    Ylianttila, Mika
    Abro, Ahmed Bux
    Gurtov, Andrei
    de Oca, Edgardo Montes
    [J]. 2015 IEEE 10TH INTERNATIONAL CONFERENCE ON INDUSTRIAL AND INFORMATION SYSTEMS (ICIIS), 2015, : 220 - 225
  • [40] Footprints: Ensuring Trusted Service Function Chaining in the World of SDN and NFV
    Pattaranantakul, Montida
    Song, Qipeng
    Tian, Yanmei
    Wang, Licheng
    Zhang, Zonghua
    Meddahi, Ahmed
    [J]. SECURITY AND PRIVACY IN COMMUNICATION NETWORKS, SECURECOMM, PT II, 2019, 305 : 287 - 301