Automatic, verifiable and optimized policy-based security enforcement for SDN-aware IoT networks

被引:16
|
作者
Bringhenti, Daniele [1 ]
Yusupov, Jalolliddin [2 ]
Zarca, Alejandro Molina [3 ]
Valenza, Fulvio [1 ]
Sisto, Riccardo [1 ]
Bernabe, Jorge Bernal [3 ]
Skarmeta, Antonio [3 ]
机构
[1] Politecn Torino, Dipartimento Automat & Informat, Turin, Italy
[2] Turin Polytech Univ, Dept Automat Control & Comp Engn, Tashkent, Uzbekistan
[3] Univ Murcia, Dept Commun & Informat Engn, Murcia, Spain
关键词
Security; IoT; SDN; INTERNET;
D O I
10.1016/j.comnet.2022.109123
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
The pervasiveness of Internet of Things (IoT) has made the management of computer networks more troublesome. The softwarized control provided by Software-Defined Networking (SDN) is not sufficient to overcome the problems raising in this context. An increasing number of attacks can, in fact, occur in SDN-aware IoT networks if the security configuration enforced on the SDN switches is manually computed and not formally verified. To mitigate this problem, this paper proposes a novel methodology which leverages Maximum Satisfiability Modulo Theories (MaxSMT) to automatically compute a formally correct and optimized allocation scheme and configuration of SDN switches by refining security policies, user-defined or derived from detected attacks. This mechanism is compliant with the main characteristics of virtualized IoT-based networks, such as the simultaneous presence of numerous interconnected devices and strict latency requirements. The feasibility and the performance of the framework developed to implement this methodology have been validated in a realistic use case.
引用
收藏
页数:12
相关论文
共 42 条
  • [21] Analysis of Policy-Based Security Management System in Software-Defined Networks
    Sood, Keshav
    Karmakar, Kallol Krishna
    Varadharajan, Vijay
    Tupakula, Uday
    Yu, Shui
    IEEE COMMUNICATIONS LETTERS, 2019, 23 (04) : 612 - 615
  • [22] A Policy-based Dynamic Security Management Mechanism for MIPv6 Networks
    Gao, Tianhan
    Guo, Nan
    Zhu, Zhiliang
    ICWMMN 08, PROCEEDINGS, 2008, : 110 - 113
  • [23] Policy-Based Security Management System for 5G Heterogeneous Networks
    Alquhayz, Hani
    Alalwan, Nasser
    Alzahrani, Ahmed Ibrahim
    Al-Bayatti, Ali H.
    Sharif, Mhd Saeed
    WIRELESS COMMUNICATIONS & MOBILE COMPUTING, 2019, 2019
  • [24] Deep reinforcement learning based transmission policy enforcement and multi-hop routing in QoS aware LoRa IoT networks
    Muthanna, Mohammed Saleh Ali
    Muthanna, Ammar
    Rafiq, Ahsan
    Hammoudeh, Mohammad
    Alkanhel, Reem
    Lynch, Stephen
    Abd El-Latif, Ahmed A.
    COMPUTER COMMUNICATIONS, 2022, 183 : 33 - 50
  • [25] Privacy-Aware Switch-Controller Mapping in SDN-Based IoT Networks
    Sridharan, Vignesh
    Liyanage, Kushan Sudheera Kalupahana
    Gurusamy, Mohan
    2020 INTERNATIONAL CONFERENCE ON COMMUNICATION SYSTEMS & NETWORKS (COMSNETS), 2020,
  • [26] An overview of QoS-aware load balancing techniques in SDN-based IoT networks
    Rostami, Mohammad
    Goli-Bidgoli, Salman
    JOURNAL OF CLOUD COMPUTING-ADVANCES SYSTEMS AND APPLICATIONS, 2024, 13 (01):
  • [27] An Energy-Efficient SDN Controller Architecture for IoT Networks With Blockchain-Based Security
    Yazdinejad, Abbas
    Parizi, Reza M.
    Dehghantanha, Ali
    Zhang, Qi
    Choo, Kim-Kwang Raymond
    IEEE TRANSACTIONS ON SERVICES COMPUTING, 2020, 13 (04) : 625 - 638
  • [28] The fuzzy-IAVOA energy-aware routing algorithm for SDN-based IoT networks
    Nazari, Amin
    Mohammadi, Reza
    Niknami, Nadia
    Jazaeri, Seyedeh Shabnam
    Wu, Jie
    INTERNATIONAL JOURNAL OF SENSOR NETWORKS, 2023, 42 (03) : 156 - 169
  • [29] Harvesting and Threat Aware Security Configuration Strategy for IEEE 802.15.4 Based IoT Networks
    Mao, Bomin
    Kawamoto, Yuichi
    Liu, Jiajia
    Kato, Nei
    IEEE COMMUNICATIONS LETTERS, 2019, 23 (11) : 2130 - 2134
  • [30] Policy-based Quality of Service and security management for multimedia services on IP networks in the RTIPA* project
    Gay, V
    Duflos, S
    Kervella, B
    Diaz, G
    Horlait, E
    MANAGEMENT OF MULTIMEDIA ON THE INTERNET, 2002, 2496 : 25 - 35