Detection and defense against network isolation attacks in software-defined networks

被引:4
|
作者
Yu, Zhipeng [1 ]
Zhu, Hui [1 ]
Xiao, Rui [1 ]
Song, Chao [1 ]
Dong, Jian [1 ]
Li, Hui [1 ]
机构
[1] Xidian Univ, Sch Cyber Engn, Xian 710126, Peoples R China
基金
中国国家自然科学基金;
关键词
MANAGEMENT; IOT; ARCHITECTURE; INTERNET;
D O I
10.1002/ett.3895
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
With the development and pervasiveness of Internet of Things (IoT) devices, Software-Defined Networks (SDN) technology has been deployed to bring great convenience to network transmission. However, SDN over IoT network still faces many challenges on devices data security. Our work demonstrates a novel attack of SDN networks, named Network Harvesting (NH). In NH, an attacker has the ability to steal the users' network privileges without the awareness of victims and the switchers. Furthermore, to solve the above attack, we construct a detection scheme and a defense scheme, named RSDetector and SpoofDefender. RSDetector detects the presence of rogue switches in the network by leveraging the prediction power of machine learning. At the same time, SpoofDefender prevents a number of spoofing attacks including NH by the global control of the SDN networks. In addition, RSDetector and SpoofDefender are also evaluated on ONOS 1.10.4 and Mininet. A good deal of simulation results demonstrate that our proposed schemes have great optimization in reducing communication and computation costs.
引用
收藏
页数:16
相关论文
共 50 条
  • [21] Toward Network-based DDoS Detection in Software-defined Networks
    Jevtic, Stefan
    Lotfalizadeh, Hamidreza
    Kim, Dongsoo S.
    PROCEEDINGS OF THE 12TH INTERNATIONAL CONFERENCE ON UBIQUITOUS INFORMATION MANAGEMENT AND COMMUNICATION (IMCOM 2018), 2018,
  • [22] Generative Adversarial Network Models for Anomaly Detection in Software-Defined Networks
    Zacaron, Alexandro Marcelo
    Lent, Daniel Matheus Brandao
    da Silva Ruffo, Vitor Gabriel
    Carvalho, Luiz Fernando
    Proenca Jr, Mario Lemes
    JOURNAL OF NETWORK AND SYSTEMS MANAGEMENT, 2024, 32 (04)
  • [23] Orchestrating Network Functions in Software-Defined Networks
    Hu, Hongchao
    Pang, Lin
    Wang, Zhenpeng
    Cheng, Guozhen
    CHINA COMMUNICATIONS, 2017, 14 (02) : 104 - 117
  • [24] Orchestrating Network Functions in Software-Defined Networks
    Hongchao Hu
    Lin Pang
    Zhenpeng Wang
    Guozhen Cheng
    中国通信, 2017, 14 (02) : 104 - 117
  • [25] Early Detection of DDoS Attacks Against Software Defined Network Controllers
    Mousavi, Seyed Mohammad
    St-Hilaire, Marc
    JOURNAL OF NETWORK AND SYSTEMS MANAGEMENT, 2018, 26 (03) : 573 - 591
  • [26] Scalable Network Virtualization in Software-Defined Networks
    Drutskoy, Dmitry
    Keller, Eric
    Rexford, Jennifer
    IEEE INTERNET COMPUTING, 2013, 17 (02) : 20 - 27
  • [27] Early Detection of DDoS Attacks Against Software Defined Network Controllers
    Seyed Mohammad Mousavi
    Marc St-Hilaire
    Journal of Network and Systems Management, 2018, 26 : 573 - 591
  • [28] Network Management Challenges in Software-Defined Networks
    Kuklinski, Slawomir
    Chemouil, Prosper
    IEICE TRANSACTIONS ON COMMUNICATIONS, 2014, E97B (01) : 2 - 9
  • [29] Virtual Network Embedding in Software-Defined Networks
    Bays, Leonardo Richter
    Gaspary, Luciano Paschoal
    Ahmed, Reaz
    Boutaba, Raouf
    NOMS 2016 - 2016 IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM, 2016, : 10 - 18
  • [30] Mitigating Timing Side-Channel Attacks in Software-Defined Networks: Detection and Response
    Shoaib, Faizan
    Chow, Yang-Wai
    Vlahu-Gjorgievska, Elena
    Nguyen, Chau
    TELECOM, 2023, 4 (04): : 877 - 900