O. Flauzac, Erick Mauricio Gallegos Robledo, Carlos Gonzalez, Fabien Mauhourat, F. Nolot
{"title":"SDN Architecture to prevent attacks with OpenFlow","authors":"O. Flauzac, Erick Mauricio Gallegos Robledo, Carlos Gonzalez, Fabien Mauhourat, F. Nolot","doi":"10.1109/WINCOM50532.2020.9272445","DOIUrl":null,"url":null,"abstract":"The impact of the Internet of Things (IoT) evolves rapidly, increasing the volume of traffic, and complicating the management of large scalable networks. Despite the security tools offered today, IoT devices are susceptible to many potential attacks. The introduction of software-defined networks (SDN) presents the opportunity for efficient management of threat detection and secure the protection of a network infrastructure. In this paper, we present the design and implementation of a network dynamic architecture including security policies and traffic monitoring decisions. In our approach, the intrusion and detection are performed by Suricata and the controller, automatically blocking attempted attacks using Openflow rules. We demonstrate the effectiveness of the proposed framework through the use of five attack scenarios. The performance results improve the rapid response time under possible attacks and flexible management of secure flow rules with Openflow.","PeriodicalId":283907,"journal":{"name":"2020 8th International Conference on Wireless Networks and Mobile Communications (WINCOM)","volume":"58 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2020-10-28","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2020 8th International Conference on Wireless Networks and Mobile Communications (WINCOM)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/WINCOM50532.2020.9272445","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2
Abstract
The impact of the Internet of Things (IoT) evolves rapidly, increasing the volume of traffic, and complicating the management of large scalable networks. Despite the security tools offered today, IoT devices are susceptible to many potential attacks. The introduction of software-defined networks (SDN) presents the opportunity for efficient management of threat detection and secure the protection of a network infrastructure. In this paper, we present the design and implementation of a network dynamic architecture including security policies and traffic monitoring decisions. In our approach, the intrusion and detection are performed by Suricata and the controller, automatically blocking attempted attacks using Openflow rules. We demonstrate the effectiveness of the proposed framework through the use of five attack scenarios. The performance results improve the rapid response time under possible attacks and flexible management of secure flow rules with Openflow.
物联网(Internet of Things, IoT)的影响发展迅速,使流量增加,同时也使大型可扩展网络的管理复杂化。尽管今天提供了安全工具,但物联网设备容易受到许多潜在攻击。软件定义网络(SDN)的引入为有效管理威胁检测和安全保护网络基础设施提供了机会。在本文中,我们提出了一个网络动态架构的设计和实现,包括安全策略和流量监控决策。在我们的方法中,入侵和检测由Suricata和控制器执行,使用Openflow规则自动阻止尝试的攻击。我们通过使用五种攻击场景来证明所提出框架的有效性。性能结果提高了对可能的攻击的快速响应时间和使用Openflow对安全流规则的灵活管理。