A Security Enforcement Framework for SDN Controller Using Game Theoretic Approach

被引:8
|
作者
Priyadarsini, Madhukrishna [1 ]
Bera, Padmalochan [2 ]
Das, Sajal K. [3 ]
Rahman, Mohammad Ashiqur [4 ]
机构
[1] KIIT Deemed Univ, Bhubaneswar 751024, India
[2] Indian Inst Technol, Bhubaneswar 752050, India
[3] Missouri Univ Sci & Technol, Rolla, MO 65409 USA
[4] Florida Int Univ, Miami, FL 33199 USA
基金
俄罗斯基础研究基金会;
关键词
SDN; security; trust model; risk verification; attack model; vulnerability analysis; INTERNET;
D O I
10.1109/TDSC.2022.3158690
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Software-defined networking (SDN) has gained significant attention as the future deployment platform for the Internet and enterprise networks. The major advantages of SDN include effective traffic management, dynamic configuration of policy and flow rules, and better scalability with heterogeneous traffic requirements. However, centralized network control and the use of OpenFlow protocols introduce various security challenges for the underlying network. The attacks on the SDN controller is critical as it hosts all network control functions. Motivated by a systematic analysis of different attack scenarios in SDN using the STRIDE attack model, this article presents an effective security enforcement framework for proactive prevention of potential attacks on SDN controllers. First, based on a signaling game approach, we design a trust-based controller attack detection (TCAD) model that calculates the trust value of each incoming packet to take necessary action. Next, we propose a risk-based attack prevention (RAP) model that detects and filters malicious traffic flows in the network. Finally, we evaluate our proposed security enforcement framework on different scenarios with varying traffic requirements and by injecting attacks based on the STRIDE model. Experimental results show 95% accuracy in the potential attack detection and prevention.
引用
收藏
页码:1500 / 1515
页数:16
相关论文
共 50 条
  • [21] Security Aspects: A Framework for Enforcement of Security Policies using AOP
    Ayed, Samiha
    Idrees, Muhammad Sabir
    Cuppens-Boulahia, Nora
    Cuppens, Frederic
    Pinto, Monica
    Fuentes, Lidia
    2013 INTERNATIONAL CONFERENCE ON SIGNAL-IMAGE TECHNOLOGY & INTERNET-BASED SYSTEMS (SITIS), 2013, : 301 - 308
  • [22] SDN-Based Security Enforcement Framework for Data Sharing Systems of Smart Healthcare
    Meng, Yunfei
    Huang, Zhiqiu
    Shen, Guohua
    Ke, Changbo
    IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2020, 17 (01): : 308 - 318
  • [23] A game theoretic framework for evaluation of the impacts of hackers diversity on security measures
    Moayedi, Behzad Zare
    Azgomi, Mohammad Abdollahi
    RELIABILITY ENGINEERING & SYSTEM SAFETY, 2012, 99 : 45 - 54
  • [24] A game-theoretic approach to stochastic security and dependability evaluation
    Sallhammar, Karin
    Helvik, Bjarne E.
    Knapskog, Sven J.
    DASC 2006: 2ND IEEE INTERNATIONAL SYMPOSIUM ON DEPENDABLE, AUTONOMIC AND SECURE COMPUTING, PROCEEDINGS, 2006, : 61 - +
  • [25] Game-Theoretic Approach Towards Network Security A Review
    Tom, Litti
    2015 INTERNATIONAL CONFERENCED ON CIRCUITS, POWER AND COMPUTING TECHNOLOGIES (ICCPCT-2015), 2015,
  • [26] Game-Theoretic Analysis for Security of Various Software-Defined Networking (SDN) Architectures
    Qi, Chao
    Wu, Jiangxing
    Chen, Hongchang
    Yu, Hongtao
    Hu, Hongchao
    Cheng, Guozhen
    2017 IEEE 85TH VEHICULAR TECHNOLOGY CONFERENCE (VTC SPRING), 2017,
  • [27] Network Slicing on SDN using FlowVisor and POX Controller to Traffic Isolation Enforcement
    Kurniawan, M. T.
    Fathinuddin, Muhammad
    Widiyanti, Hilda Aries
    Simanjuntak, Grace R.
    2021 7TH INTERNATIONAL CONFERENCE ON ENGINEERING AND EMERGING TECHNOLOGIES (ICEET 2021), 2021, : 223 - 228
  • [28] Game-Theoretic Framework for Malicious Controller Detection in Software Defined Networks
    Sridharan, Vignesh
    Gurusamy, Mohan
    IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2021, 18 (03): : 3107 - 3120
  • [29] A Game Theoretic Approach to Design a Resilient Controller For a Nonlinear Discrete System
    Salehghaffari, Hossein
    Krishnamurthy, Prashanth
    Khorrami, Farshad
    IFAC PAPERSONLINE, 2017, 50 (01): : 387 - 392
  • [30] A Game Theoretic Framework for Modeling Adversarial Cyber Security Game Among Attackers, Defenders, and Users
    Ryutov, Tatyana
    Orosz, Michael
    Blythe, James
    von Winterfeldt, Detlof
    SECURITY AND TRUST MANAGEMENT (STM 2015), 2015, 9331 : 274 - 282