TD-RA policy-enforcement framework for an SDN-based IoT architecture

被引:4
|
作者
Lahlou, Sara [1 ]
Moukafih, Youness [1 ,2 ]
Sebbar, Anass [1 ]
Zkik, Karim [3 ]
Boulmalf, Mohammed [1 ]
Ghogho, Mounir [1 ]
机构
[1] Int Univ Rabat, TICLab, Rabat, Morocco
[2] Univ Lorraine, LORIA INRIA Lorraine, Lorraine, France
[3] ESAIP Grad Sch Engn, Angers, France
关键词
SDN-based IoT; Security; Machine learning; Threat detection; Policy enforcement; SOFTWARE-DEFINED NETWORKS; ATTACK; SECURITY; INTERNET;
D O I
10.1016/j.jnca.2022.103390
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Internet of Things (IoT) has been suffering from increasing security threats since many years which compromise the whole network security. Automating the management of IoT devices helps in implementing security measures within communication systems. Software Defined Networking (SDN) has been introduced as a new networking approach that enables this automation. Many approaches were developed to mitigate IoT attacks in SDN-based IoT networks. Some studies investigated the prevention of flooding attacks, while others tried to cover broader attack surfaces. However, their proposed methods are time consuming and resource-exhausting as they use complex algorithms. In this paper, we propose a lightweight secure Threat Detection (TD) and Rule Automation (RA) framework namely "TD-RA'' to effectively detect and mitigate different cyber-security threats in an SDN-based IoT environment. The proposed solution is composed of a Binary and Multi-class Classification Modules (BCM/MCM) for IoT threat detection and a Policy-Enforcement Module (PEM) for attack mitigation. Different machine learning methods have been implemented and compared to solve the classification problems. It is shown that for binary classification, the Decision Tree method achieves the highest accuracy which is around 98.7%, while for multi-class classification, Random Forest achieves the highest accuracy which is around 91.1%. The experimental results show that the proposed framework can successfully detect abnormal traffic and prevent IoT threats through SDN with smaller network overhead and high performance. Moreover, the overall processing time of our security modules is significantly smaller than that of existing solutions by reaching a mean value of 6 ms. This paper also introduces a large-scale architecture that comprises clusters of controllers to maintain high availability of network services. Such an integrated security approach, including detection and mitigation techniques, provides IT industries with reliable security measures that can be implemented to increase SDN-based IoT system responsiveness to different IoT attacks.
引用
收藏
页数:20
相关论文
共 50 条
  • [31] An SDN-based Virtual Cell Framework for Enhancing the QoE in TD-LTE Pico Cells
    Costanzo, Salvatore
    Shrivastava, Rudraksh
    Xenakis, Dionysis
    Samdanis, Konstantinos
    Grace, David
    Merakos, Lazaros
    2015 SEVENTH INTERNATIONAL WORKSHOP ON QUALITY OF MULTIMEDIA EXPERIENCE (QOMEX), 2015,
  • [32] Certrust: An SDN-Based Framework for the Trust of Certificates against Crossfire Attacks in IoT Scenarios
    Yan, Lei
    Ma, Maode
    Li, Dandan
    Huang, Xiaohong
    Ma, Yan
    Xie, Kun
    CMES-COMPUTER MODELING IN ENGINEERING & SCIENCES, 2023, 134 (03): : 2137 - 2162
  • [33] A Secured Framework for SDN-Based Edge Computing in IoT-Enabled Healthcare System
    Li, Junxia
    Cai, Jinjin
    Khan, Fazlullah
    Rehman, Ateeq Ur
    Balasubramaniam, Venki
    Sun, Jiangfeng
    Venu, P.
    IEEE ACCESS, 2020, 8 : 135479 - 135490
  • [34] Usage Control Policy Enforcement in SDN-based Clouds: A Dynamic Availability Service Use Case
    Toumi, Khalifa
    Idrees, Muhammad Sabir
    Charmet, Fabien
    Yaich, Reda
    Blanc, Gregory
    PROCEEDINGS OF 2016 IEEE 18TH INTERNATIONAL CONFERENCE ON HIGH PERFORMANCE COMPUTING AND COMMUNICATIONS; IEEE 14TH INTERNATIONAL CONFERENCE ON SMART CITY; IEEE 2ND INTERNATIONAL CONFERENCE ON DATA SCIENCE AND SYSTEMS (HPCC/SMARTCITY/DSS), 2016, : 578 - 585
  • [35] A SDN-based Aeronautical Communications Network Architecture
    Hu, Yim-Fun
    Ali, Muhammad
    Doanh Luong
    Abdo, Kanaan
    Cormbe, Quentin
    Barossi, Regis
    BenSlama, Fathia
    Benamrane, Fouad
    2018 IEEE/AIAA 37TH DIGITAL AVIONICS SYSTEMS CONFERENCE (DASC), 2018, : 753 - 762
  • [36] Brew: A Security Policy Analysis Framework for Distributed SDN-Based Cloud Environments
    Pisharody, Sandeep
    Natarajan, Janakarajan
    Chowdhary, Ankur
    Alshalan, Abdullah
    Huang, Dijiang
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2019, 16 (06) : 1011 - 1025
  • [37] A SDN-based network architecture for cloud resiliency
    Fressancourt, Antoine
    Gagnaire, Maurice
    2015 12TH ANNUAL IEEE CONSUMER COMMUNICATIONS AND NETWORKING CONFERENCE, 2015, : 479 - 484
  • [38] SDMob: SDN-Based Mobility Management for IoT Networks
    Rabet, Iliar
    Selvaraju, Shunmuga Priyan
    Fotouhi, Hossein
    Alves, Mario
    Vahabi, Maryam
    Balador, Ali
    Bjorkman, Mats
    JOURNAL OF SENSOR AND ACTUATOR NETWORKS, 2022, 11 (01)
  • [39] An SDN-based Architecture for Network-as-a-Service
    Manthena, Mani Prashanth Varma
    van Adrichem, Niels L. M.
    van den Broek, Casper
    Kuipers, Fernando
    2015 1ST IEEE CONFERENCE ON NETWORK SOFTWARIZATION (NETSOFT), 2015,
  • [40] SDN-Based Architecture for Big Data Network
    Xu, Yuhua
    Sun, Zhe
    Sun, Zhixin
    2017 INTERNATIONAL CONFERENCE ON CYBER-ENABLED DISTRIBUTED COMPUTING AND KNOWLEDGE DISCOVERY (CYBERC), 2017, : 513 - 516