A Bayesian Game-Theoretic Intrusion Detection System for Hypervisor-Based Software Defined Networks in Smart Grids

被引:14
|
作者
Niazi, Rumaisa Aimen [1 ]
Faheem, Yasir [1 ]
机构
[1] COMSATS Univ Islamabad, Dept Comp Sci, Islamabad Campus, Islamabad 45550, Pakistan
关键词
Software-defined networks; smart grids; DDoS attacks; hypervisor; Bayesian game theory;
D O I
10.1109/ACCESS.2019.2924968
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
y The future smart grids (SGs) require advanced capabilities in terms of automation, processing, monitoring, and communication. The most crucial component in the successful sustainability of SGs is communication management. In the vSDNs, a hypervisor is implemented between a physical infrastructure and a control plane that abstracts the underlying SDN infrastructure into multiple isolated virtual slices, i.e., we can have multiple vSDNs each with its controller. For that purpose, the virtualized SDNs offer a promising solution as they offer better network management, programmability, and virtualization. However, vSDN-based SGs are prone to many security issues. To disturb operations of the SGs, the security of the vSDN can be compromised by manipulating the jeopardized switches in the DDoS attacks to repress the resources of vSDN controllers. To prevent the exploitation of a vSDN-based SG architecture and preserve its limited resources, this paper formulates the strategic interaction between a hypervisor monitoring its vSDN controllers and the source of new flow requests potentially launching a DDoS attack, via compromised switches, as a non-cooperative dynamic Bayesian game of intrusion detection. Our game model enables a hypervisor to distribute its limited resources to monitor guest vSDN controllers optimally. The performance evaluation via simulations shows that our game model enables a hypervisor not only to increase the probability of detecting distributed attacks and minimize false positives but at the same time, its monitoring costs get reduced as the allocation of resources to monitor vSDN controllers depends upon its belief about the source of the attacks that it forms based on its observation.
引用
收藏
页码:88656 / 88672
页数:17
相关论文
共 50 条
  • [1] Hypervisor-based Cloud Intrusion Detection System
    Nikolai, Jason
    Wang, Yong
    2014 INTERNATIONAL CONFERENCE ON COMPUTING, NETWORKING AND COMMUNICATIONS (ICNC), 2014, : 989 - 993
  • [2] Cloud security in the age of adaptive adversaries: A game theoretic approach to hypervisor-based intrusion detection
    Sadia
    Saadat, Ahsan
    Faheem, Yasir
    Abaid, Zainab
    Fraz, Muhammad Moazam
    JOURNAL OF SYSTEMS ARCHITECTURE, 2024, 156
  • [3] Game-Theoretic Approach to Malicious Controller Detection in Software Defined Networks
    Sridharan, Vignesh
    Gurusamy, Mohan
    2018 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2018,
  • [4] Game-Theoretic Framework for Malicious Controller Detection in Software Defined Networks
    Sridharan, Vignesh
    Gurusamy, Mohan
    IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2021, 18 (03): : 3107 - 3120
  • [5] Anomaly Detection in Smart Grids based on Software Defined Networks
    Jung, Oliver
    Smith, Paul
    Magin, Julian
    Reuter, Lenhard
    PROCEEDINGS OF THE 8TH INTERNATIONAL CONFERENCE ON SMART CITIES AND GREEN ICT SYSTEMS (SMARTGREENS), 2019, : 157 - 164
  • [6] GUIDEX: A Game-Theoretic Incentive-Based Mechanism for Intrusion Detection Networks
    Zhu, Quanyan
    Fung, Carol
    Boutaba, Raouf
    Basar, Tamer
    IEEE JOURNAL ON SELECTED AREAS IN COMMUNICATIONS, 2012, 30 (11) : 2220 - 2230
  • [7] Design of Hypervisor-based Integrated Intrusion Detection System in Cloud Computing Environment
    Wang, Chih-Hung
    Chen, Xuan-Liang
    INTELLIGENT SYSTEMS AND APPLICATIONS (ICS 2014), 2015, 274 : 972 - 981
  • [8] A game-theoretic intrusion detection model for mobile ad hoc networks
    Otrok, Hadi
    Mohammed, Noman
    Wang, Lingyu
    Debbabi, Mourad
    Bhattacharya, Prabir
    COMPUTER COMMUNICATIONS, 2008, 31 (04) : 708 - 721
  • [9] Game-Theoretic Approach to Attack Planning and Controller Placement in Software Defined Networks
    Junosza-Szaniawski, Konstanty
    Nogalski, Dariusz
    2023 INTERNATIONAL CONFERENCE ON MILITARY COMMUNICATIONS AND INFORMATION SYSTEMS, ICMCIS, 2023,
  • [10] A Game-Theoretic Framework for Robust Optimal Intrusion Detection in Wireless Sensor Networks
    Moosavi, Hussein
    Bui, Francis Minhthang
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2014, 9 (09) : 1367 - 1379