首页> 外文期刊>Internet of Things Journal, IEEE >SDN-Enabled Secure IoT Architecture
【24h】

SDN-Enabled Secure IoT Architecture

机译:支持SDN的安全IOT架构

获取原文
获取原文并翻译 | 示例
           

摘要

The Internet of Things (IoT) is increasingly being used in applications ranging from precision agriculture to critical national infrastructure by deploying a large number of resource-constrained devices in hostile environments. These devices are being exploited to launch attacks in cyber systems. As a result, security has become a significant concern in the design of IoT-based applications. In this article, we present a security architecture for IoT networks by leveraging the underlying features supported by software-defined networks (SDNs). Our security architecture not only restricts network access to authenticated IoT devices but also enforces fine granular policies to secure the flows in the IoT network infrastructure. The authentication is achieved using a lightweight protocol to authenticate IoT devices. Authorization is achieved using a dynamic policy driven approach. Such an integrated security approach involving authentication of IoT devices and enables authorized flows to protect IoT networks from malicious IoT devices and attacks. We have implemented and validated our architecture using ONOS SDN Controller and Raspbian Virtual Machines, and demonstrated how the proposed security mechanisms can counteract malware packet injection, DDoS attacks using Mirai, spoofing/masquerading, and man-in-the-middle attacks. An analysis of the security and performance of the proposed security mechanisms and their applications is presented in this article.
机译:事物互联网(IOT)越来越多地用于通过在敌对环境中部署大量资源受限设备来越来越多地用于从精密农业到关键的国家基础架构。这些设备正在被利用以在网络系统中发射攻击。因此,安全性在基于IOT的应用程序设计中已成为一个重要问题。在本文中,我们通过利用软件定义的网络(SDN)支持的底层功能来为IoT网络提供安全架构。我们的安全架构不仅限制了对经过身份验证的IOT设备的网络访问,还强制执行细粒度策略,以保护IOT网络基础架构中的流程。使用轻量级协议来实现认证以进行身份​​验证IOT设备。使用动态策略驱动方法实现授权。这种涉及物联网设备的身份验证的综合安全方法,并启用授权流,以保护来自恶意物联网设备和攻击的IOT网络。我们已经使用ONOS SDN控制器和RASPBian虚拟机实施了我们的架构,并证明了所提出的安全机制如何抵消使用Mirai,欺骗/伪装和中间人攻击的恶意软件数据包注入,DDOS攻击。本文介绍了拟议的安全机制的安全性和绩效及其申请的分析。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号