The current paper addresses relevant network security vulnerabilities introduced by network devices within the emerging paradigm of Internet of Things (IoT) as well as the urgent need to mitigate the negative effects of some types of Distributed Denial of Service (DDoS) attacks that try to explore those security weaknesses. We design and implement a Software-Defined Intrusion Detection System (IDS) that reactively impairs the attacks at its origin, ensuring the normal operation of the network infrastructure. Our proposal includes an IDS that automatically detects several DDoS attacks, and then as an attack is detected, it notifies a Software Defined Networking (SDN) controller. The current proposal also downloads some convenient traffic forwarding decisions from the SDN controller to network devices. The evaluation results suggest that our proposal timely detects several types of cyber-attacks based on DDoS, mitigates their negative impacts on the network performance, and ensures the correct data delivery of normal traffic. Our work sheds light on the programming relevance over an abstracted view of the network infrastructure to timely detect a Botnet exploitation, mitigate malicious traffic at its source, and protect benign traffic.
翻译:本文论述网络装置在新兴的物联网范式(IoT)中引入的网络安全弱点,以及迫切需要减轻某些类型的分散拒绝提供服务(DDoS)攻击的负面影响,试图探索这些安全弱点。我们设计并实施了软件定义入侵探测系统(IDS),从源头被动地损害攻击,确保网络基础设施的正常运行。我们的提案包括一个国际数据系统,自动探测到若干次DDoS攻击,然后在发现攻击时,通知一个软件定义网络控制器。目前的提案还下载了SDN控制器的一些方便的交通转发决定,下载到网络装置。评价结果表明,我们的提案及时检测出基于DDoS的几类网络攻击,减轻其对网络性能的不利影响,确保正常交通的正确数据传输。我们的工作揭示了网络基础设施抽象视角下的编程相关性,以便及时探测博特网的开发,减少恶意交通源,保护良性交通。