A Bayesian Game-Theoretic Intrusion Detection System for Hypervisor-Based Software Defined Networks in Smart Grids

被引:14
|
作者
Niazi, Rumaisa Aimen [1 ]
Faheem, Yasir [1 ]
机构
[1] COMSATS Univ Islamabad, Dept Comp Sci, Islamabad Campus, Islamabad 45550, Pakistan
关键词
Software-defined networks; smart grids; DDoS attacks; hypervisor; Bayesian game theory;
D O I
10.1109/ACCESS.2019.2924968
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
y The future smart grids (SGs) require advanced capabilities in terms of automation, processing, monitoring, and communication. The most crucial component in the successful sustainability of SGs is communication management. In the vSDNs, a hypervisor is implemented between a physical infrastructure and a control plane that abstracts the underlying SDN infrastructure into multiple isolated virtual slices, i.e., we can have multiple vSDNs each with its controller. For that purpose, the virtualized SDNs offer a promising solution as they offer better network management, programmability, and virtualization. However, vSDN-based SGs are prone to many security issues. To disturb operations of the SGs, the security of the vSDN can be compromised by manipulating the jeopardized switches in the DDoS attacks to repress the resources of vSDN controllers. To prevent the exploitation of a vSDN-based SG architecture and preserve its limited resources, this paper formulates the strategic interaction between a hypervisor monitoring its vSDN controllers and the source of new flow requests potentially launching a DDoS attack, via compromised switches, as a non-cooperative dynamic Bayesian game of intrusion detection. Our game model enables a hypervisor to distribute its limited resources to monitor guest vSDN controllers optimally. The performance evaluation via simulations shows that our game model enables a hypervisor not only to increase the probability of detecting distributed attacks and minimize false positives but at the same time, its monitoring costs get reduced as the allocation of resources to monitor vSDN controllers depends upon its belief about the source of the attacks that it forms based on its observation.
引用
收藏
页码:88656 / 88672
页数:17
相关论文
共 50 条
  • [21] Game-Theoretic Based Scheduling for Demand-Side Management in 5G Smart Grids
    Saghezchi, Firooz B.
    Saghezchi, Fatemeh B.
    Nascimento, Alberto
    Rodriguez, Jonathan
    2015 IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATION (ISCC), 2015, : 8 - 12
  • [22] IDSaaS in SDN: Intrusion Detection System as a Service in Software Defined Networks
    Chukwu, Julian
    Osamudiamen, Ose
    Matrawy, Ashraf
    2016 IEEE CONFERENCE ON COMMUNICATIONS AND NETWORK SECURITY (CNS), 2016, : 356 - 357
  • [23] Risk based intrusion detection system in software defined networking
    Chetouane, Ameni
    Karoui, Kamel
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2024, 36 (09):
  • [24] Intrusion Detection System based on Software Defined Network Firewall
    Sayeed, Mohd Abuzar
    Sayeed, Mohd Asim
    Saxena, Sharad
    2015 1ST INTERNATIONAL CONFERENCE ON NEXT GENERATION COMPUTING TECHNOLOGIES (NGCT), 2015, : 379 - 382
  • [25] Flexible Network-based Intrusion Detection and Prevention System on Software-defined Networks
    An Le
    Phuong Dinh
    Hoa Le
    Ngoc Cuong Tran
    2015 INTERNATIONAL CONFERENCE ON ADVANCED COMPUTING AND APPLICATIONS (ACOMP), 2015, : 106 - 111
  • [26] Specification-based Intrusion Detection for Home Area Networks in Smart Grids
    Jokar, Paria
    Nicanfar, Hasen
    Leung, Victor C. M.
    2011 IEEE INTERNATIONAL CONFERENCE ON SMART GRID COMMUNICATIONS (SMARTGRIDCOMM), 2011,
  • [27] HMM-based Intrusion Detection System for Software Defined Networking
    Hurley, Trae
    Perdomo, Jorge E.
    Perez-Pons, Alexander
    2016 15TH IEEE INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND APPLICATIONS (ICMLA 2016), 2016, : 617 - 621
  • [28] Intrusion Detection and Prevention for ZigBee-Based Home Area Networks in Smart Grids
    Jokar, Paria
    Leung, Victor C. M.
    IEEE TRANSACTIONS ON SMART GRID, 2018, 9 (03) : 1800 - 1811
  • [29] SD-IIDS: intelligent intrusion detection system for software-defined networks
    Shaji, Neena Susan
    Muthalagu, Raja
    Pawar, Pranav Mothabhau
    MULTIMEDIA TOOLS AND APPLICATIONS, 2024, 83 (04) : 11077 - 11109
  • [30] SD-IIDS: intelligent intrusion detection system for software-defined networks
    Neena Susan Shaji
    Raja Muthalagu
    Pranav Mothabhau Pawar
    Multimedia Tools and Applications, 2024, 83 : 11077 - 11109