Research Area:  Software Defined Networks
The exponential growth of devices connected to the network has resulted in the development of new Internet of Things (IoT) applications and online services, which may have diverse and dynamic requirements on received quality. Although, the emerging software-defined networking (SDN) approach can be leveraged for the IoT environment, to dynamically achieve differentiated quality levels for different IoT tasks in very heterogeneous wireless networking scenarios, the open interfaces in SDN introduces new network attacks, which may make SDN-based IoT malfunctioned. The challenges lies in securely using SDN for IoT systems. To address this challenge, we design a SDN-based data transfer security model middlebox-guard (M-G). M-G aims at reducing network latency, and properly manage dataflow to ensure the network run safely. First, according to different security policies, middleboxes related to the defined secure policies, are placed at the most appropriate locations, using dataflow abstraction and a heuristic algorithm. Next, to avoid any middlebox becoming a hotspot, an offline integer linear program (ILP) pruning algorithm is proposed in M-G, to tackle switch volume constraints. In addition, an online linear program (LP) formulation is come up to handle load balance. Finally, secure mechanisms are proposed to handle different attacks. And network routing is solved flexibly, through dataflow management protocol, which are formulated via combining tunnels and tags. Experimental results demonstrate that this model can improve security performance and manage dataflow effectively in SDN-based IoT system.
Keywords:  
Dataflow management
Internet of Things (IoT)
middlebox
security
software-defined networking (SDN)
Author(s) Name:  Yanbing Liu; Yao Kuang; Yunpeng Xiao; Guangxia Xu
Journal name:  IEEE Internet of Things Journal
Conferrence name:  
Publisher name:  IEEE
DOI:  10.1109/JIOT.2017.2779180
Volume Information:  Volume: 5, Issue: 1, February 2018, Page(s): 257 - 268
Paper Link:   https://ieeexplore.ieee.org/abstract/document/8125690