Defending Against New-Flow Attack in SDN-Based Internet of Things

被引:41
|
作者
Xu, Tong [1 ]
Gao, Deyun [1 ]
Dong, Ping [1 ]
Zhang, Hongke [1 ]
Foh, Chuan Heng [2 ]
Chao, Han-Chieh [3 ]
机构
[1] Beijing Jiaotong Univ, Sch Elect & Informat Engn, Natl Engn Lab Next Generat Internet Interconnect, Beijing 100044, Peoples R China
[2] Univ Surrey, Inst Commun Syst, Dept Elect & Elect Engn, IC 5G, Surrey GU1 2UX, England
[3] Natl Dong Hwa Univ, Shoufeng Township 974, Taiwan
来源
IEEE ACCESS | 2017年 / 5卷
关键词
Internet of Things; software-defined networking; OpenFlow; communication system security; new-flow attack; SOFTWARE-DEFINED NETWORKING;
D O I
10.1109/ACCESS.2017.2666270
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Recently, the Internet of Things (IoT) is attracting significant attention from both academia and industry. To connect the huge amount of IoT devices effectively, software-defined networking (SDN) is considered as a promising way because of its centralized network management and programmable routing logic. However, due to the limited resources in both the data plane and the control plane, SDN is vulnerable to the new-flow attack, which can disable the SDN-based IoT by exhausting the switches or the controller. Therefore, in this paper, we propose a smart security mechanism (SSM) to defend against the new-flow attack. The SSM uses the standard southbound and northbound interfaces of SDN, and it includes a low-cost method that monitors the new-flow attack by reusing the asynchronous messages on the control link. The monitor method can differentiate the new-flow attack from the normal flow burst by checking the hit rate of the flow entries. Based on the monitoring result, the SSM uses a dynamic access control method to mitigate the new-flow attack by perceiving the behavior of the security middleware in the IoT. The dynamic access control method can intercept the attack flows at their access switch. Extensive simulations and testbed-based experiments are conducted and the corresponding results verify the feasibility of our claims.
引用
收藏
页码:3431 / 3443
页数:13
相关论文
共 50 条
  • [1] An SDN-based Network Architecture for Internet of Things
    Zhang, Zhiyong
    Wang, Rui
    Cai, Xiaojun
    Jia, Zhiping
    IEEE 20TH INTERNATIONAL CONFERENCE ON HIGH PERFORMANCE COMPUTING AND COMMUNICATIONS / IEEE 16TH INTERNATIONAL CONFERENCE ON SMART CITY / IEEE 4TH INTERNATIONAL CONFERENCE ON DATA SCIENCE AND SYSTEMS (HPCC/SMARTCITY/DSS), 2018, : 980 - 985
  • [2] Mitigating New-Flow Attack with SDNSnapshot in P4-based SDN
    Cai, Yun-Zhan
    Lin, Ting-Yu
    Wang, Yu-Ting
    Tuan, Ya-Pei
    Tsai, Meng-Hsun
    2022 23RD ASIA-PACIFIC NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM (APNOMS 2022), 2022, : 227 - 230
  • [3] SDN-based Differentiated Traffic Flow Management for Industrial Internet of Things Environments
    Callegati, Franco
    Campi, Aldo
    Contoli, Chiara
    Di Santi, Silvio
    Ghiselli, Nicola
    Giannelli, Carlo
    Pernafini, Alessandro
    Zamagna, Riccardo
    26TH IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATIONS (IEEE ISCC 2021), 2021,
  • [4] A SDN-based Architecture for Horizontal Internet of Things Services
    Li, Yuhong
    Su, Xiang
    Riekki, Jukka
    Kanter, Theo
    Rahmani, Rahim
    2016 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2016,
  • [5] Performance Evaluation of SDN-based Internet of Space Things
    Kak, Ahan
    Guven, Eray
    Ergin, Utku E.
    Akyildiz, Ian F.
    2018 IEEE GLOBECOM WORKSHOPS (GC WKSHPS), 2018,
  • [6] SDN-Based Data Transfer Security for Internet of Things
    Liu, Yanbing
    Kuang, Yao
    Xiao, Yunpeng
    Xu, Guangxia
    IEEE INTERNET OF THINGS JOURNAL, 2018, 5 (01): : 257 - 268
  • [7] An SDN-based Approach For Defending Against Reflective DDoS Attacks
    Lukaseder, Thomas
    StOlzle, Kevin
    Kleber, Stephan
    Erb, Benjamin
    Kargl, Frank
    PROCEEDINGS OF THE 2018 IEEE 43RD CONFERENCE ON LOCAL COMPUTER NETWORKS (LCN), 2018, : 299 - 302
  • [8] SDN-based Multicast Communication Framework for Industrial Internet of Things
    Xu J.-Q.
    Lu J.-X.
    Li H.-Q.
    Zhao H.
    Dongbei Daxue Xuebao/Journal of Northeastern University, 2023, 44 (02): : 192 - 198
  • [9] An SDN-based framework for QoS routing in internet of underwater things
    Reza Mohammadi
    Amin Nazari
    Mohammad Nassiri
    Mauro Conti
    Telecommunication Systems, 2021, 78 : 253 - 266
  • [10] Forwarding Rule Multiplexing for Scalable SDN-Based Internet of Things
    Zhang, Xiaoning
    Yu, Shui
    Zhang, Ji
    Xu, Zhichao
    IEEE INTERNET OF THINGS JOURNAL, 2019, 6 (02): : 3373 - 3385