首页> 外文期刊>IEEE transactions on industrial informatics >An SDN-Enabled Pseudo-Honeypot Strategy for Distributed Denial of Service Attacks in Industrial Internet of Things
【24h】

An SDN-Enabled Pseudo-Honeypot Strategy for Distributed Denial of Service Attacks in Industrial Internet of Things

机译:启用S​​DN的伪蜜罐策略,用于工业互联网上的分布式拒绝服务攻击

获取原文
获取原文并翻译 | 示例

摘要

Leveraging high-performance software-defined networks (SDNs) to manage industrial Internet of Things (IIoT) devices has become a promising trend; the SDN is expected to be the next generation as a unified and virtualized network platform that provides unprecedented automation, flexibility, and efficiency. As the core of business applications and sensitive data storage, the SDN is vulnerable to distributed denial-of-service (DDoS) attacks in IIoT environment that numerous requests are sent to the SDN to interrupt its services. In the traditional defense systems, honeypots have shown great promises in resisting DDoS attacks. In this paper, we reveal a new attack that can identify honeypots to invalidate their protection. In addition, we analyze the optimal strategies of attackers, so that they can find the best time to carry on attacks. To protect SDN from such a kind of anti-honeypot attacks, we propose a pseudo-honeypot game (PHG) strategy with theoretical performance guarantee. We prove several groups of Bayesian-Nash Equilibrium in the PHG strategy. Moreover, we show that these strategies can achieve the optimal equilibrium between legitimate users and attackers. The proposed honeypot strategies can provide dynamic protection for SDN. Hence, malicious attacks under our strategies can be effectively controlled. Finally, we evaluate our proposals on a testbed, and experimental results show that our proposals can effectively resist DDoS attacks with lower energy consumption compared with the existing methods.
机译:利用高性能软件定义的网络(SDNS)来管理工业物联网(IIT)设备已成为一个有前途的趋势;预计SDN将是下一代作为统一和虚拟​​化网络平台,提供前所未有的自动化,灵活性和效率。作为业务应用程序的核心和敏感数据存储,SDN容易受到IIT环境中的分布式拒绝服务(DDOS)攻击,即许多请求被发送到SDN以中断其服务。在传统的防御系统中,蜜罐在抵制DDOS袭击方面表现出很大的承诺。在本文中,我们揭示了一种新的攻击,可以识别蜜罐,使他们的保护失效。此外,我们还分析了攻击者的最佳策略,以便他们可以找到攻击的最佳时间。为了保护SDN免受这样一种抗蜜罐攻击,我们提出了一种具有理论性能保证的伪蜜罐游戏(PHG)策略。我们证明了几个贝叶斯纳什均衡的PHG策略。此外,我们表明这些策略可以实现合法用户和攻击者之间的最佳均衡。拟议的蜜罐策略可以为SDN提供动态保护。因此,可以有效地控制我们战略下的恶意攻击。最后,我们评估了测试用用品的提案,实验结果表明,与现有方法相比,我们的建议可以有效地抵抗能量消耗较低的DDOS攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号