首页> 外文期刊>Journal of network and computer applications >SEAL: SDN based secure and agile framework for protecting smart city applications from DDoS attacks
【24h】

SEAL: SDN based secure and agile framework for protecting smart city applications from DDoS attacks

机译:SEAL:基于SDN的安全敏捷框架,可保护智能城市应用程序免受DDoS攻击

获取原文
获取原文并翻译 | 示例
           

摘要

Evolution of smart cities induces critical challenges related to cyber and network security. The increased reliance of a smart city on Information and Communication Technologies (ICT) infrastructure improves automation, efficiency, and sustainability of city services. However, it also poses enormous challenges for ensuring continued operations and services at all times and especially under cyber-attacks. Any lapse in cyber security can lead to critical disaster across the city. Distributed Denial of Service (DDoS) attacks are considered to be the most predominant and prevalent cyber-attacks. We believe that smart city could consist of numerous applications with varying level of network and security requirements. Therefore, providing an adaptive mechanism against DDoS attacks for all applications in a smart city is a key challenge. Further, considering the wide-scale requirements of a smart city, developing an adaptive and flexible solution is a key requirement. Considering these requirements, this paper presents SEAL (SEcure and AgiLe) - a novel Software Defined Networking (SDN) based adaptive framework for protecting smart city applications against DDoS attacks. The SEAL framework leverages key characteristics of SDN such as the global visibility, centralized control, and programmability to enhance the security and resilience. SEAL is capable of effectively detecting and mitigating DDoS attacks not only on application servers but also on network resources. SEAL is also unique in this regard that it provides application specific DDoS attack security solution instead of static threshold mechanism. Moreover, inherently distributed architecture of the SEAL framework ensures fault tolerance, scalability and reliability of the smart city. The SEAL framework comprises three modules, namely D-Defense, A-Defense and C-Defense. These modules collectively provide a mechanism to detect and mitigate DDoS attack on smart city applications and the network infrastructure. Adaptability in SEAL is achieved through implementing customized version of estimated-weighted moving average (EWMA) filters. Three types of filters, Proactive Filter, Active Filter, and Passive Filter are proposed and implemented to compute the dynamic threshold in real time for various types of applications. Experimental evaluation of the SEAL framework has been conducted to establish the efficacy of the framework and its components in detecting and mitigating DDoS attacks. The results prove that SEAL is able to detect and mitigate DDoS attacks effectively. The focus of the SEAL framework is to protect smart city applications, however, the SEAL framework can potentially be utilized in a wide range of systems.
机译:智慧城市的发展引发了与网络和网络安全相关的重大挑战。智慧城市对信息和通信技术(ICT)基础设施的依赖性不断提高,从而改善了城市服务的自动化,效率和可持续性。但是,这对于确保始终(尤其是在网络攻击下)的持续运营和服务也构成了巨大的挑战。网络安全方面的任何失误都可能导致整个城市的严重灾难。分布式拒绝服务(DDoS)攻击被认为是最主要和最普遍的网络攻击。我们认为,智慧城市可能由众多具有不同级别的网络和安全要求的应用程序组成。因此,为智能城市中的所有应用程序提供针对DDoS攻击的自适应机制是一项关键挑战。此外,考虑到智能城市的广泛需求,开发自适应和灵活的解决方案是关键要求。考虑到这些要求,本文提出了SEAL(SEcure和AgiLe)-一种新颖的基于软件定义网络(SDN)的自适应框架,用于保护智能城市应用程序免受DDoS攻击。 SEAL框架利用SDN的关键特性(例如全局可见性,集中控制和可编程性)来增强安全性和弹性。 SEAL能够有效地检测和缓解DDoS攻击,不仅在应用程序服务器上,而且在网络资源上。 SEAL在这方面也很独特,它提供了特定于应用程序的DDoS攻击安全解决方案,而不是静态阈值机制。此外,SEAL框架的固有分布式体系结构可确保智能城市的容错性,可伸缩性和可靠性。 SEAL框架包含三个模块,即D-Defense,A-Defense和C-Defense。这些模块共同提供了一种机制,可以检测和缓解对智能城市应用程序和网络基础结构的DDoS攻击。 SEAL的适应性是通过实现估计加权移动平均值(EWMA)过滤器的定制版本来实现的。提出并实现了三种类型的滤波器,即主动滤波器,主动滤波器和无源滤波器,以针对各种类型的应用实时计算动态阈值。已经对SEAL框架进行了实验评估,以建立该框架及其组件在检测和缓解DDoS攻击中的功效。结果证明,SEAL能够有效地检测和缓解DDoS攻击。 SEAL框架的重点是保护智能城市应用程序,但是,SEAL框架可以在广泛的系统中使用。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号