Dynamic Attack-Resilient Routing in Software Defined Networks

被引:13
|
作者
Mohan, Purnima Murali [1 ]
Gurusamy, Mohan [1 ]
Lim, Teng Joon [1 ]
机构
[1] Natl Univ Singapore, Dept Elect & Comp Engn, Singapore 117583, Singapore
关键词
Software defined networks; multipath routing; reliability; resilience; constrained routing; WIRELESS SENSOR NETWORKS; MULTIPATH; SECURE; SYSTEMS;
D O I
10.1109/TNSM.2018.2846294
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The scale of connected devices in the modern communication network and its heterogeneous nature have made securing the network more challenging. However, with the advent of software defined networking (SDN), the algorithmic complexity is handled at a centralized control plane and the network elements perform only data forwarding based on control plane decisions. This enables researchers to design innovative security protocols at the control plane to dynamically defend against attacks. In this paper, we propose a dynamic attack-resilient routing (ARR) approach and develop an optimization formulation for fragmented multipath routing taking reliability and load into consideration for SDN-enabled networks. Though erasure encoding has been well studied for resilient data storage, it is rarely mentioned in the context of network routing owing to its complexity, redundancy, and difficulty of satisfying practical routing constraints. In this paper, we dynamically determine the optimal route for erasure-encoded fragments of the data, in terms of attack resilience, under the constraint on allowable encoding redundancy. Since the ARR algorithm is computationally prohibitive for larger networks, we develop a heuristic solution for the same using a multipath-tree. The proposed algorithm dynamically routes the data fragments along a set of reliable and lightly loaded paths to achieve multipath diversity and thereby improve data availability at the destination even in the presence of attacks. We demonstrate the effectiveness of our proposed approach in terms of weighted path reliability, resilience, and blocking performance through simulations.
引用
收藏
页码:1146 / 1160
页数:15
相关论文
共 50 条
  • [21] Attack-Resilient TLS Certificate Transparency
    Khan, Salabat
    Zhu, Liehuang
    Zhang, Zijian
    Rahim, Mussadiq Abdul
    Khan, Khalid
    Li, Meng
    [J]. IEEE ACCESS, 2020, 8 : 98958 - 98973
  • [22] Fragmentation-based Multipath Routing for Attack Resilience in Software Defined Networks
    Mohan, Purnima Murali
    Lim, Teng Joon
    Gurusamy, Mohan
    [J]. 2016 IEEE 41ST CONFERENCE ON LOCAL COMPUTER NETWORKS (LCN), 2016, : 583 - 586
  • [23] An Attack-Resilient Cooperative Control Strategy of Multiple Distributed Generators in Distribution Networks
    Liu, Yun
    Xin, Huanhai
    Qu, Zhihua
    Gan, Deqiang
    [J]. IEEE TRANSACTIONS ON SMART GRID, 2016, 7 (06) : 2923 - 2932
  • [24] Towards Attack-Resilient Geometric Data Perturbation
    Chen, Keke
    Sun, Gordon
    Liu, Ling
    [J]. PROCEEDINGS OF THE SEVENTH SIAM INTERNATIONAL CONFERENCE ON DATA MINING, 2007, : 78 - +
  • [25] Lightweight and Attack-resilient PUF for Internet of Things
    Rajan, Akshayhari
    Sankaran, Sriram
    [J]. 2020 6TH IEEE INTERNATIONAL SYMPOSIUM ON SMART ELECTRONIC SYSTEMS (ISES 2020) (FORMERLY INIS), 2020, : 139 - 142
  • [26] An Attack-Resilient Channel Assignment MAC Protocol
    Zang, Wanyu
    Gu, Qijun
    Yu, Meng
    Liu, Peng
    [J]. 2009 INTERNATIONAL CONFERENCE ON NETWORK-BASED INFORMATION SYSTEMS, 2009, : 246 - +
  • [27] Flow aggregation through dynamic routing overlaps in software defined networks
    Zhao, Zhipeng
    Yang, Weidong
    Wu, Bin
    [J]. COMPUTER NETWORKS, 2020, 176
  • [28] Dynamic Routing for Network Throughput Maximization in Software-Defined Networks
    Huang, Meitian
    Liang, Weifa
    Xu, Zichuan
    Xu, Wenzheng
    Guo, Song
    Xu, Yinlong
    [J]. IEEE INFOCOM 2016 - THE 35TH ANNUAL IEEE INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATIONS, 2016,
  • [29] Attack-Resilient State Estimation in the Presence of Noise
    Pajic, Miroslav
    Tabuada, Paulo
    Lee, Insup
    Pappas, George J.
    [J]. 2015 54TH IEEE CONFERENCE ON DECISION AND CONTROL (CDC), 2015, : 5827 - 5832
  • [30] On Data-driven Attack-resilient Gaussian Process Regression for Dynamic Systems
    Kim, Hunmin
    Guo, Pinyao
    Zhu, Minghui
    Liu, Peng
    [J]. 2020 AMERICAN CONTROL CONFERENCE (ACC), 2020, : 2981 - 2986