Detection and defense against network isolation attacks in software-defined networks

被引:4
|
作者
Yu, Zhipeng [1 ]
Zhu, Hui [1 ]
Xiao, Rui [1 ]
Song, Chao [1 ]
Dong, Jian [1 ]
Li, Hui [1 ]
机构
[1] Xidian Univ, Sch Cyber Engn, Xian 710126, Peoples R China
基金
中国国家自然科学基金;
关键词
MANAGEMENT; IOT; ARCHITECTURE; INTERNET;
D O I
10.1002/ett.3895
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
With the development and pervasiveness of Internet of Things (IoT) devices, Software-Defined Networks (SDN) technology has been deployed to bring great convenience to network transmission. However, SDN over IoT network still faces many challenges on devices data security. Our work demonstrates a novel attack of SDN networks, named Network Harvesting (NH). In NH, an attacker has the ability to steal the users' network privileges without the awareness of victims and the switchers. Furthermore, to solve the above attack, we construct a detection scheme and a defense scheme, named RSDetector and SpoofDefender. RSDetector detects the presence of rogue switches in the network by leveraging the prediction power of machine learning. At the same time, SpoofDefender prevents a number of spoofing attacks including NH by the global control of the SDN networks. In addition, RSDetector and SpoofDefender are also evaluated on ONOS 1.10.4 and Mininet. A good deal of simulation results demonstrate that our proposed schemes have great optimization in reducing communication and computation costs.
引用
收藏
页数:16
相关论文
共 50 条
  • [41] DDoS attacks on data plane of software-defined network: are they possible?
    Wu, Xiaotong
    Liu, Meng
    Dou, Wanchun
    Yu, Shui
    SECURITY AND COMMUNICATION NETWORKS, 2016, 9 (18) : 5444 - 5459
  • [42] Timing-based Reconnaissance and Defense in Software-defined Networks
    Sonchack, John
    Dubey, Anurag
    Aviv, Adam J.
    Smith, Jonathan M.
    Keller, Eric
    32ND ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE (ACSAC 2016), 2016, : 89 - 100
  • [43] Packet Injection Attack and Its Defense in Software-Defined Networks
    Deng, Shuhua
    Gao, Xing
    Lu, Zebin
    Gao, Xieping
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2018, 13 (03) : 695 - 705
  • [44] Intrusion Prevention Scheme Against Rank Attacks for Software-Defined Low Power IoT Networks
    Miranda, Christian
    Kaddoum, Georges
    Boukhtouta, Amine
    Madi, Taous
    Alameddine, Hyame Assem
    IEEE ACCESS, 2022, 10 : 129970 - 129984
  • [45] HCOBASAA: Countermeasure Against Sinkhole Attacks in Software-Defined Wireless Sensor Cognitive Radio Networks
    Sejaphala, Lanka
    Velempini, Mthulisi
    Dlamini, Sabelo Velemseni
    2018 INTERNATIONAL CONFERENCE ON ADVANCES IN BIG DATA, COMPUTING AND DATA COMMUNICATION SYSTEMS (ICABCD), 2018,
  • [46] Programming the Network: Application Software Faults in Software-Defined Networks
    Jagadeesan, Lalita J.
    Mendiratta, Veena
    2016 IEEE 27TH INTERNATIONAL SYMPOSIUM ON SOFTWARE RELIABILITY ENGINEERING WORKSHOPS (ISSREW), 2016, : 125 - 131
  • [47] A Software Approach for Mitigation of DoS Attacks on SDN's (Software-Defined Networks)
    Lotlikar, Trupti
    Shah, Deven
    SOFT COMPUTING IN DATA ANALYTICS, SCDA 2018, 2019, 758 : 333 - 342
  • [48] An Approach for Detection of Attacks in Software Defined Networks
    Chippalkatti, Omkar
    Nimbhorkar, S. U.
    2017 INTERNATIONAL CONFERENCE ON INNOVATIONS IN INFORMATION, EMBEDDED AND COMMUNICATION SYSTEMS (ICIIECS), 2017,
  • [49] An Extension Approach for Threat Detection and Defense of Software-Defined Networking
    Xu, Hui
    Wang, Chunzhi
    Chen, Hongwei
    INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2016, 10 (02): : 365 - 374
  • [50] Network Softwarization and Parallel Networks: Beyond Software-Defined Networks
    Wang, Fei-Yue
    Yang, Liuqing
    Cheng, Xiang
    Han, Shuangshuang
    Yang, Jian
    IEEE NETWORK, 2016, 30 (04): : 60 - 65