Defending Against New-Flow Attack in SDN-Based Internet of Things

被引:41
|
作者
Xu, Tong [1 ]
Gao, Deyun [1 ]
Dong, Ping [1 ]
Zhang, Hongke [1 ]
Foh, Chuan Heng [2 ]
Chao, Han-Chieh [3 ]
机构
[1] Beijing Jiaotong Univ, Sch Elect & Informat Engn, Natl Engn Lab Next Generat Internet Interconnect, Beijing 100044, Peoples R China
[2] Univ Surrey, Inst Commun Syst, Dept Elect & Elect Engn, IC 5G, Surrey GU1 2UX, England
[3] Natl Dong Hwa Univ, Shoufeng Township 974, Taiwan
来源
IEEE ACCESS | 2017年 / 5卷
关键词
Internet of Things; software-defined networking; OpenFlow; communication system security; new-flow attack; SOFTWARE-DEFINED NETWORKING;
D O I
10.1109/ACCESS.2017.2666270
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Recently, the Internet of Things (IoT) is attracting significant attention from both academia and industry. To connect the huge amount of IoT devices effectively, software-defined networking (SDN) is considered as a promising way because of its centralized network management and programmable routing logic. However, due to the limited resources in both the data plane and the control plane, SDN is vulnerable to the new-flow attack, which can disable the SDN-based IoT by exhausting the switches or the controller. Therefore, in this paper, we propose a smart security mechanism (SSM) to defend against the new-flow attack. The SSM uses the standard southbound and northbound interfaces of SDN, and it includes a low-cost method that monitors the new-flow attack by reusing the asynchronous messages on the control link. The monitor method can differentiate the new-flow attack from the normal flow burst by checking the hit rate of the flow entries. Based on the monitoring result, the SSM uses a dynamic access control method to mitigate the new-flow attack by perceiving the behavior of the security middleware in the IoT. The dynamic access control method can intercept the attack flows at their access switch. Extensive simulations and testbed-based experiments are conducted and the corresponding results verify the feasibility of our claims.
引用
收藏
页码:3431 / 3443
页数:13
相关论文
共 50 条
  • [31] New-flow based DDoS attacks in SDN: Taxonomy, rationales, and research challenges
    Singh, Maninder Pal
    Bhandari, Abhinav
    COMPUTER COMMUNICATIONS, 2020, 154 (154) : 509 - 527
  • [32] A Research Review on SDN-Based DDOS Attack Detection
    Zhu, Weidong
    Yi, Xiujuan
    PROCEEDINGS OF THE 2017 INTERNATIONAL CONFERENCE ON MANAGEMENT SCIENCE AND MANAGEMENT INNOVATION (MSMI 2017), 2017, 31 : 145 - 149
  • [33] An SDN-Based Framework for E2E QoS Guarantee in Internet of Things Devices
    Ali, Jehad
    Song, Houbing Herbert
    Roh, Byeong-hee
    IEEE INTERNET OF THINGS JOURNAL, 2025, 12 (01): : 605 - 622
  • [34] Application-Aware SDN-Based Iterative Reconfigurable Routing Protocol for Internet of Things (IoT)
    Shafique, Ayesha
    Cao, Guo
    Aslam, Muhammad
    Asad, Muhammad
    Ye, Dengpan
    SENSORS, 2020, 20 (12) : 1 - 22
  • [35] SDN-based ARP Attack Detection for Cloud Centers
    Ma, Huan
    Ding, Hao
    Yang, Yang
    Mi, Zhenqiang
    Zhang, Miao
    IEEE 12TH INT CONF UBIQUITOUS INTELLIGENCE & COMP/IEEE 12TH INT CONF ADV & TRUSTED COMP/IEEE 15TH INT CONF SCALABLE COMP & COMMUN/IEEE INT CONF CLOUD & BIG DATA COMP/IEEE INT CONF INTERNET PEOPLE AND ASSOCIATED SYMPOSIA/WORKSHOPS, 2015, : 1049 - 1054
  • [36] Defending Against Cyber-Attacks on the Internet of Things
    Abdalrahman, Ghazi Abdalla
    Varol, Hacer
    2019 7TH INTERNATIONAL SYMPOSIUM ON DIGITAL FORENSICS AND SECURITY (ISDFS), 2019,
  • [37] A SDN-based traffic estimation approach in the internet of vehicles
    Yang, Yuanqi
    WIRELESS NETWORKS, 2021,
  • [38] An SDN-based Framework for Managing Internet Exchange Points
    Cunha Martins, Luis Felipe
    Cunha, Italo
    Guedes, Dorgival
    2018 IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATIONS (ISCC), 2018, : 1001 - 1006
  • [39] SDN-based security low-latency data storage and distribution scheme for industrial Internet of Things
    Zhang, Kewang
    Shu, Zhixu
    JOURNAL OF COMPUTATIONAL METHODS IN SCIENCES AND ENGINEERING, 2024, 24 (4-5) : 2943 - 2956
  • [40] Differentially Private Tensor Train Decomposition in Edge-Cloud Computing for SDN-Based Internet of Things
    Nie, Xin
    Yang, Laurence T.
    Feng, Jun
    Zhang, Shunli
    IEEE INTERNET OF THINGS JOURNAL, 2020, 7 (07) : 5695 - 5705