SODA: A software-defined security framework for IoT environments

被引:21
|
作者
Kim, Yeonkeun [1 ]
Nam, Jaehyun [1 ]
Park, Taejune [1 ]
Scott-Hayward, Sandra [2 ]
Shin, Seungwon [1 ]
机构
[1] Korea Adv Inst Sci & Technol, 291 Daehak Ro, Daejeon 34141, South Korea
[2] Queens Univ Belfast, Univ Rd, Belfast BT7 1NN, Antrim, North Ireland
基金
英国工程与自然科学研究理事会;
关键词
IoT security; Software-defined networking; Network function virtualization; Access control; INTERNET; SYSTEM;
D O I
10.1016/j.comnet.2019.106889
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
The Internet of Things (IoT), based on interconnected devices, enables a variety of elegant new services that could not be realized in a traditional environment, and many of these services harvest the information of a potentially sensitive and private nature belonging to individual users. Unfortunately, existing security functions used to protect such information are difficult to implement in an IoT environment due to the widely varying capacities, functionalities, and security requirements of IoT devices. In this work, to protect against unrestricted accesses to other devices and information extortion from these devices, we propose SODA, a secure IoT gateway that enables a device-side dynamic access control and is capable of deploying various security services to protect sensitive and private information. To show its effectiveness and practicality, we assume that a large number of IoT devices are crowded around an IoT gateway, and we implement a prototype of SODA for such an environment based on software-defined-networking (SDN) and integrate virtual network functions (VNFs) over network function virtualization (NFV) on top of a real IoT device. From our evaluation, we demonstrate how SODA mitigates real-world attacks through its security functions, and presents how it satisfies the performance requirements of a real environment. (C) 2019 Elsevier B.V. All rights reserved.
引用
收藏
页数:13
相关论文
共 50 条
  • [1] KalKi: A Software-Defined IoT Security Platform
    Echeverria, Sebastian
    Lewis, Grace
    Mazzotta, Craig
    Grabowski, Christopher
    O'Meara, Kyle
    Vasudevan, Amit
    Novakouski, Marc
    McCormack, Matthew
    Sekar, Vyas
    [J]. 2020 IEEE 6TH WORLD FORUM ON INTERNET OF THINGS (WF-IOT), 2020,
  • [2] Software Defined IoT Security Framework
    Salman, Ola
    Elhajj, Imad
    Chehab, Ali
    Kayssi, Ayman
    [J]. 2017 FOURTH INTERNATIONAL CONFERENCE ON SOFTWARE DEFINED SYSTEMS (SDS), 2017, : 75 - 80
  • [3] A Software-Defined Security Framework for Power IoT Cloud-Edge Environment
    Qiu, Rixuan
    Fu, Yu
    Le, Jian
    Zheng, Fuyong
    Qi, Gan
    Peng, Chao
    Li, Yuancheng
    [J]. International Journal of Network Security, 2022, 24 (06) : 1031 - 1041
  • [4] A Security Evaluation Framework for Software-Defined Network Architectures in Data Center Environments
    Ivkic, Igor
    Thiede, Dominik
    Race, Nicholas
    Broadbent, Matthew
    Gouglidis, Antonios
    [J]. PROCEEDINGS OF THE 13TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING AND SERVICES SCIENCE, CLOSER 2023, 2023, : 277 - 288
  • [5] SDSA: A Framework of a Software-Defined Security Architecture
    Liu Yanbing
    Lu Xingyu
    Jian Yi
    Xiao Yunpeng
    [J]. CHINA COMMUNICATIONS, 2016, 13 (02) : 178 - 188
  • [6] MUD-Based Behavioral Profiling Security Framework for Software-Defined IoT Networks
    Krishnan, Prabhakar
    Jain, Kurunandan
    Buyya, Rajkumar
    Vijayakumar, Pandi
    Nayyar, Anand
    Bilal, Muhammad
    Song, Houbing
    [J]. IEEE INTERNET OF THINGS JOURNAL, 2022, 9 (09) : 6611 - 6622
  • [7] A Security-aware Software-defined IoT Network Architecture
    Zuo, Xinbin
    Pang, Xue
    Zhang, Pengping
    Zhang, Junsan
    Dong, Tao
    Zhang, Peiying
    [J]. 2020 IEEE COMPUTING, COMMUNICATIONS AND IOT APPLICATIONS (COMCOMAP), 2021,
  • [8] A comprehensive security assessment framework for software-defined networks
    Lee, Seungsoo
    Kim, Jinwoo
    Woo, Seungwon
    Yoon, Changhoon
    Scott-Hayward, Sandra
    Yegneswaran, Vinod
    Porras, Phillip
    Shin, Seungwon
    [J]. COMPUTERS & SECURITY, 2020, 91
  • [9] A Framework for Security Services based on Software-Defined Networking
    Jeong, Jaehoon
    Seo, Jihyeok
    Cho, Geumhwan
    Kim, Hyoungshick
    Park, Jung-Soo
    [J]. 2015 IEEE 29TH INTERNATIONAL CONFERENCE ON ADVANCED INFORMATION NETWORKING AND APPLICATIONS WORKSHOPS WAINA 2015, 2015, : 150 - 153
  • [10] DELTA: A Security Assessment Framework for Software-Defined Networks
    Lee, Seungsoo
    Yoon, Changhoon
    Lee, Chanhee
    Shin, Seungwon
    Yegneswaran, Vinod
    Porras, Phillip
    [J]. 24TH ANNUAL NETWORK AND DISTRIBUTED SYSTEM SECURITY SYMPOSIUM (NDSS 2017), 2017,