Defending Against New-Flow Attack in SDN-Based Internet of Things

被引:41
|
作者
Xu, Tong [1 ]
Gao, Deyun [1 ]
Dong, Ping [1 ]
Zhang, Hongke [1 ]
Foh, Chuan Heng [2 ]
Chao, Han-Chieh [3 ]
机构
[1] Beijing Jiaotong Univ, Sch Elect & Informat Engn, Natl Engn Lab Next Generat Internet Interconnect, Beijing 100044, Peoples R China
[2] Univ Surrey, Inst Commun Syst, Dept Elect & Elect Engn, IC 5G, Surrey GU1 2UX, England
[3] Natl Dong Hwa Univ, Shoufeng Township 974, Taiwan
来源
IEEE ACCESS | 2017年 / 5卷
关键词
Internet of Things; software-defined networking; OpenFlow; communication system security; new-flow attack; SOFTWARE-DEFINED NETWORKING;
D O I
10.1109/ACCESS.2017.2666270
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Recently, the Internet of Things (IoT) is attracting significant attention from both academia and industry. To connect the huge amount of IoT devices effectively, software-defined networking (SDN) is considered as a promising way because of its centralized network management and programmable routing logic. However, due to the limited resources in both the data plane and the control plane, SDN is vulnerable to the new-flow attack, which can disable the SDN-based IoT by exhausting the switches or the controller. Therefore, in this paper, we propose a smart security mechanism (SSM) to defend against the new-flow attack. The SSM uses the standard southbound and northbound interfaces of SDN, and it includes a low-cost method that monitors the new-flow attack by reusing the asynchronous messages on the control link. The monitor method can differentiate the new-flow attack from the normal flow burst by checking the hit rate of the flow entries. Based on the monitoring result, the SSM uses a dynamic access control method to mitigate the new-flow attack by perceiving the behavior of the security middleware in the IoT. The dynamic access control method can intercept the attack flows at their access switch. Extensive simulations and testbed-based experiments are conducted and the corresponding results verify the feasibility of our claims.
引用
收藏
页码:3431 / 3443
页数:13
相关论文
共 50 条
  • [41] SDN-based Regulated Flow Routing in MANETs
    Streit, Klement
    Schmitt, Corinna
    Giannelli, Carlo
    2020 IEEE INTERNATIONAL CONFERENCE ON SMART COMPUTING (SMARTCOMP), 2020, : 73 - 80
  • [42] SDN-based DDoS Attack Detection with Cross-Plane Collaboration and Lightweight Flow Monitoring
    Yang, Xiangrui
    Han, Biao
    Sun, Zhigang
    Huang, Jinfeng
    GLOBECOM 2017 - 2017 IEEE GLOBAL COMMUNICATIONS CONFERENCE, 2017,
  • [43] SDN-based Attack Detection in Wireless Local Area Networks
    Cwalinski, Radoslaw
    Koenig, Hartmut
    2018 4TH IEEE CONFERENCE ON NETWORK SOFTWARIZATION AND WORKSHOPS (NETSOFT), 2018, : 207 - 211
  • [44] PivotWall: SDN-Based Information Flow Control
    OConnor, T. J.
    Enck, William
    Petullo, W. Michael
    Verma, Akash
    PROCEEDINGS OF THE SYMPOSIUM ON SDN RESEARCH (SOSR'18), 2018,
  • [45] Adaptive Suspicious Prevention for Defending DoS Attacks in SDN-Based Convergent Networks
    Nhu-Ngoc Dao
    Kim, Joongheon
    Park, Minho
    Cho, Sungrae
    PLOS ONE, 2016, 11 (08):
  • [46] The DAO Induction Attack Against the RPL-based Internet of Things
    Baghani, Ahmad Shabani
    Rahimpour, Sonbol
    Khabbazian, Majid
    2020 28TH INTERNATIONAL CONFERENCE ON SOFTWARE, TELECOMMUNICATIONS AND COMPUTER NETWORKS (SOFTCOM), 2020, : 379 - 383
  • [47] Digital Signature Based Countermeasure Against Puppet Attack in the Internet of Things
    Pu, Cong
    Carpenter, Logan
    2019 IEEE 18TH INTERNATIONAL SYMPOSIUM ON NETWORK COMPUTING AND APPLICATIONS (NCA), 2019, : 189 - 192
  • [48] Defending against Packet-In messages flooding attack under SDN context
    Gao, Deyun
    Liu, Zehui
    Liu, Ying
    Foh, Chuan Heng
    Zhi, Ting
    Chao, Han-Chieh
    SOFT COMPUTING, 2018, 22 (20) : 6797 - 6809
  • [49] Defending Code from the Internet of Things against Buffer Overflow
    Teixeira, Fernando A.
    Machado, Gustavo V.
    Fonseca, Pablo M.
    Pereira, Fernando M. Q.
    Wong, Hao Chi
    Nogueira, Jose M. S.
    Oliveira, Leonardo B.
    2014 BRAZILIAN SYMPOSIUM ON COMPUTER NETWORKS AND DISTRIBUTED SYSTEMS (SBRC), 2014, : 293 - 301
  • [50] Automatic Generation of Social Relationships between Internet of Things in Smart Home using SDN-based Home Cloud
    Kim, Younggi
    Lee, Younghee
    2015 IEEE 29TH INTERNATIONAL CONFERENCE ON ADVANCED INFORMATION NETWORKING AND APPLICATIONS WORKSHOPS WAINA 2015, 2015, : 662 - 667