论文标题

在软件定义的无线传感器网络中拒绝服务攻击检测

Denial of Service Attacks Detection in Software-Defined Wireless Sensor Networks

论文作者

Segura, Gustavo A. Nunez, Skaperas, Sotiris, Chorti, Arsenia, Mamatas, Lefteris, Margi, Cintia Borges

论文摘要

软件定义的网络(SDN)是一项有前途的技术,可以克服无线传感器网络(WSN)的许多挑战,尤其是在灵活性和重复使用方面。相反,在分布式拒绝服务(DDOS)攻击的一般环境中,集中化和飞机的分离转向SDN容易受到新的安全威胁。识别DDO的最新方法并不总是考虑到典型的WSN中的限制,例如计算复杂性和功率限制,而进一步的性能始终是目标。这项工作的目的是使用变更点分析提出一种轻巧但非常有效的DDOS攻击检测方法。我们的方法具有较高的检测率和线性复杂性,因此适用于WSN。我们证明了检测器在36个和100个节点的软件定义的WSN中的性能,其攻击强度不同(攻击者的数量从5%到20%的节点不等)。我们使用更改点检测器来监视两个指标的异常情况:数据包的传递速率和控制数据包上空开销。我们的结果表明,随着攻击强度的增加,我们的方法可以达到接近100%的检测率,并且也可以推断出攻击的类型。

Software-defined networking (SDN) is a promising technology to overcome many challenges in wireless sensor networks (WSN), particularly with respect to flexibility and reuse. Conversely, the centralization and the planes' separation turn SDNs vulnerable to new security threats in the general context of distributed denial of service (DDoS) attacks. State-of-the-art approaches to identify DDoS do not always take into consideration restrictions in typical WSNs e.g., computational complexity and power constraints, while further performance improvement is always a target. The objective of this work is to propose a lightweight but very efficient DDoS attack detection approach using change point analysis. Our approach has a high detection rate and linear complexity, so that it is suitable for WSNs. We demonstrate the performance of our detector in software-defined WSNs of 36 and 100 nodes with varying attack intensity (the number of attackers ranges from 5% to 20% of nodes). We use change point detectors to monitor anomalies in two metrics: the data packets delivery rate and the control packets overhead. Our results show that with increasing intensity of attack, our approach can achieve a detection rate close to100% and that the type of attack can also be inferred.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源