As a result of the ubiquitous network applications and services, exacerbated by the overarching digital revolution the need and demand for efficient and dependable connectivity solutions have surged to unprecedented levels. Quality of Service (QoS)-based routing has emerged as a critical solution, enabling service differentiation, efficient resource allocation, and improved network performance. In this study, we introduce a novel Genetic Algorithm-powered QoS-aware Cross-Network Traffic Engineering framework,GATE-BC, at the confluence of Software Defined Networking (SDN) and Blockchain (BC) technologies.GATE-BCorchestrates end-to-end (E2E) QoS traffic, providing resource-efficient, reliable, and latency-tolerant delivery of intelligent network services in BC-enabled SDNs. Leveraging BC features such as decentralization, transparency, and immutability,GATE-BCeliminates the need for centralized entities in QoS-supported cross-network routing models. We compareGATE-BCframework with three other traffic management and engineering approaches: QoSChain (QC), Hierarchical Routing Approach (HRA), and Distributed Routing Approach (DRA). The extensive simulations reveal thatGATE-BCoutperforms the other routing strategies in terms of Path Setup Time (PST), Network Message Overhead (NMO), Request Acceptance Ratio (RAR), Network Bandwidth Consumption (NBC), Average Path Length (APL), and Average Network Length (ANL) metrics under various network topologies. Furthermore,GATE-BCemploys three different feasible path selection strategies based on bandwidth (GATE-BC_BW), delay (GATE-BC_D), and reliability (GATE-BC_R) QoS parameters to satisfy the service levels requested.
Low-speed internet can negatively impact incident response by causing delayed detection, ineffective response, poor collaboration, inaccurate analysis, and increased risk. Slow internet speeds can delay the receipt and analysis of data, making it difficult for security teams to access the relevant information and take action, leading to a fragmented and inadequate response. All of these factors can increase the risk of data breaches and other security incidents and their impact on IoT-enabled communication. This study combines virtual network function (VNF) technology with software -defined networking (SDN) called virtual network function software-defined networking (VNFSDN). The adoption of the VNFSDN approach has the potential to enhance network security and efficiency while reducing the risk of cyberattacks. This approach supports IoT devices that can analyze large volumes of data in real time. The proposed VNFSDN can dynamically adapt to changing security requirements and network conditions for IoT devices. VNFSDN uses threat filtration and threat-capturing and decision-driven algorithms to minimize cyber risks for IoT devices and enhance network performance. Additionally, the integrity of IoT devices is safeguarded by addressing the three risk categories of data manipulation, insertion, and deletion. Furthermore, the prioritized delegated proof of stake (PDPoS) consensus variant is integrated with VNFSDN to combat attacks. This variant addresses the scalability issue of blockchain technology by providing a safe and adaptable environment for IoT devices that can quickly be scaled up and down to pull together the changing demands of the organization, allowing IoT devices to efficiently utilize resources. The PDPoS variant provides flexibility to IoT devices to proactively respond to potential security threats, preventing or mitigating the impact of cyberattacks. The proposed VNFSDN dynamically adapts to the changing security requirements and network conditions, improving network resiliency and enabling proactive threat detection. Finally, we compare the proposed VNFSDN to existing state-of-the-art approaches. According to the results, the proposed VNFSDN has a 0.08 ms minimum response time, a 2% packet loss rate, 99.5% network availability, a 99.36% threat detection rate, and a 99.77% detection accuracy with 1% malicious nodes.
The rapid evolution of the IoT has paved the way for new opportunities in smart city domains, including e-health, smart homes, and precision agriculture.However, this proliferation of services demands effective SLAs between customers and service providers, especially for critical services.Difficulties arise in maintaining the integrity of such agreements, especially in vulnerable wireless environments.This study proposes a novel SLA management model that uses an SDN-Enabled WSN consisting of wireless nodes to interact with smart contracts in a straightforward manner.The proposed model ensures the persistence of network metrics and SLA provisions through smart contracts, eliminating the need for intermediaries to audit payment and compensation procedures.The reliability and verifiability of the data prevents doubts from the contracting parties.To meet the high-performance requirements of the blockchain in the proposed model, low-cost algorithms have been developed for implementing blockchain technology in wireless sensor networks with low-energy and low-capacity nodes.Furthermore, a cryptographic signature control code is generated by wireless nodes using the in-memory private key and the dynamic random key from the smart contract at runtime to prevent tampering with data transmitted over the network.This control code enables the verification of end-to-end data signatures.The efficient generation of dynamic keys at runtime is ensured by the flexible and high-performance infrastructure of the SDN architecture.
This paper presents a novel QoE provisioning system with micropayment for Voice of Internet Protocol (VoIP) and video streaming services (QmV2). QmV2leverages Software Defined Networking (SDN) to provide guaranteed QoE and the distributed ledger IOTA technology micropayment. More specifically, QmV2's SDN controller has an innovative QoE calculation mechanism utilizing Mean Opinion Score (MOS) that considers service flow monitoring parameters, including packet loss rate and delay. Upon a QoE request and receiving the IOTA payment, QmV2can provide the requested QoE for the service flow. We have implemented and evaluated QmV2using the POX SDN controller, the network emulator Mininet-WiFi with VoIP and video streaming. The results confirm QmV2delivers satisfactory user experiences (i.e., aligned with the guaranteed MOS values) for VoIP and video streaming applications with the confirmed IOTA payment.
Andrei C. Azevedo, Eder J. Scheid, Muriel Figueredo Franco, Lisandro Zambenedetti Granville
Besides the main blockchain use-case of exchanging cryptocurrencies, Distributed Applications (DApps) can also be developed on top of such a technology. However, due to the size of popular blockchains and price, testing these DApps in a real-world environment becomes challenging. Thus, blockchain emulators were proposed to address such as issue. This paper presents the experience of emulating an Ethereum network using a Docker-based lightweight testbed developed for Software Defined Networks (SDN).
Nischal Aryal, Fariba Ghaffari, E. Bertin, Noël Crespi
The Open Radio Access Network (O-RAN) introduces openness and intelligence into the existing, tightly-coupled RAN ecosystem. Openness promotes collaboration among various vendors to provide diverse components (hardware, software, or both) for the RAN ecosystem, while intelligence handles complex network activities using Artificial Intelligence (AI). Although O-RAN design addresses many issues in traditional RANs, such as vendor lock-in, lack of flexibility, and limited innovation, it raises several management and security concerns related to collaboration, access management, privacy, trust, and availability. Distributed Ledger Technologies (DLTs) offer a viable method of establishing trust among entities, managing resources efficiently, and automating complex network tasks. Several DLT properties, such as distributed architecture, high automation through smart contracts, immutability, and transparency, could position DLT-based ideas as game changers in a multi-vendor O-RAN ecosystem. Furthermore, this technology has the potential to introduce new business models and establish secure and trusted micro-payments among vendors and network participants. In this paper, we first present a taxonomy for discussing existing O-RAN challenges. Based on the taxonomy, we then examine the possibility of incorporating DLT-based solutions in O-RAN architecture to address these challenges.
Blockchain and other decentralized databases, known as distributed ledgers, are designed to store information online where all trusted network members can update the data with transparency. The dynamics of ledger's development can be mathematically represented by a directed acyclic graph (DAG). One essential property of a properly functioning shared ledger is that all network members holding a copy of the ledger agree on a sequence of information added to the ledger, which is referred to as consensus and is known to be related to a structural property of DAG called one-endedness. In this paper, we consider a model of distributed ledger with sequential stochastic arrivals that mimic attachment rules from the IOTA cryptocurrency. We first prove that the number of leaves in the random DAG is bounded by a constant infinitely often through the identification of a suitable martingale, and then prove that a sequence of specific events happens infinitely often. Combining those results we establish that, as time goes to infinity, the IOTA DAG is almost surely one-ended.
Low Power and Lossy Networks (LLNs) are a class of networks characterized by constrained resources, intermittent connectivity, and potential lossy links. These networks find applications in various domains such as Internet of Things (IoT), smart grids, and industrial automation. However, the inherent challenges of LLNs, including energy efficiency, routing reliability, and scalability, have prompted researchers to explore innovative solutions. Blockchain, a de -centralized and secure distributed ledger technology, has emerged as a potential candidate to address these challenges. This systematic review aims to comprehensively analyze and evaluate the existing research on utilizing blockchain solutions for routing protocols in LLNs. The review follows a structured methodology to identify, categorize, and critically assess the state -of -the -art research contributions in this domain.
Internet of Things (IoT)-enabled Smart Grid (SG) network is envisioned as the next-generation network for intelligent and efficient electric power transmission. In SG environment, the Smart Meters (SMs) mostly exchange services and data from Service Providers (SPs) via insecure public channel. This makes the entire SG ecosystem vulnerable to various security threats. Motivated from the aforementioned challenges, we incorporate Digital Twin (DT) technology, Software-Defined Networking (SDN), Deep Learning (DL) and blockchain into the design of a novel SG network. Specifically, a secure communication channel is first designed using an authentication method based on blockchain technology that has the ability to withstand a number of well-known assaults. Second, a new DL architecture that includes a self-attention mechanism, a Bidirectional-Gated Recurrent Unit (Bi-GRU) model, fully connected layers, and a softmax classifier is designed to enhance the attack detection process in SG environments. To deliver low latency and real-time services, the SDN is next employed as the network’s backbone to send requests from SMs to a global SDN controller. DT technology is finally integrated into the SDN control plane, which stores the operating states and behavior models of SMs and communicates with SMs. The efficiency of the proposed framework is demonstrated by the blockchain implementation used in the SG network to assess computing time for the various numbers of transactions per block. Finally, the numerical results based on the N-BaIoT dataset shows better intrusion detection.
Abstract SDN revolutionises network management by providing a centralised controller that enables flexible and effortless configuration of networks. However, this flexibility also leads to a vulnerability that enables the adversary to trick the security system into allowing the installation of unauthorised flow rules in the switches. Blockchain provides us with a way to protect against malicious tampering with flow rules by storing them in the distributed ledger. In this work, we propose FTISCON, a mechanism to preserve the integrity of the OpenFlow flow table that utilizes blockchain technology. We employ the Ethereum Private Blockchain to implement the proof-of-concept and conduct a comparative analysis of the proposed scheme and existing related schemes, evaluating their performance in terms of delay, computation time, transaction cost, and detection rate. The proposed work is found to perform better in each of these. The study results suggest that the proposed approach offers a practical and efficient remedy to prevent flow modification attacks within SDN networks.
With fast evolution of computer and networking technologies, more and more systems and applications are based on interconnecting different devices and systems to form the Internet-of-Something: things, vehicles, and even bodies. Many among those systems require permanent, distributed data storage facilities which are being increasingly implemented using replicated, tamper-proof blockchain ledgers. Most, if not all, of those problems are exacerbated, rather than solved, by blockchain technology. In addition, the use of blockchain brings many challenges that include efficient and reliable data distribution; efficient and collusion-proof consensus mechanisms; efficient coverage of wide geographical areas; and a plethora of existing security- and privacy-related constraints on the networks.
Yanbo Song, Tao Feng, Chungang Yang, Xinru Mi · 6 authors
Software-defined network (SDN) is characterized by its programmability, flexibility, and the separation of control and data planes. However, SDN still have many challenges, particularly concerning the security of network information synchronization and network element registration. Blockchain and intent-driven networks are recent technologies to establish secure and intelligent SDN. This article investigates the blockchain-based architecture and intent-driven mechanisms to implement intent-driven security software-defined networks (IS2N). Specifically, we propose a novel four-layer architecture of the IS2N with security capabilities. We integrate an intent-driven security management mechanism in the IS2N to achieve automate network security management. Finally, we develop an IS2N platform with blockchain middle-layer to achieve security capabilities and security store network-level snapshots, such as device registration and OpenFlow messages. Our simulations show that IS2N is more flexible than conventional strategies at resolving problems during network operations and has a minimal effect on the SDN.
To address the problems that current studies for enhancing network accountability based on IPv6 addresses do not support cross-Autonomous Systems (AS) or restrict threatener behaviors, a distributed IPv6 Address Traceback and Threatener Restriction Mechanism (ATTRM6) based on smart contract is proposed. Tracing servers of each AS form a blockchain and invoke smart contract functions to store address information of different ASes on the blockchain. When IPv6 address traceback is needed across ASes, the traceback server of a specific AS reads addresses information stored on the blockchain to identify the threatener. Considering the restriction scheme for threatener associated with IPv6 addresses, and proposing a Punishment-Forgiveness Policy (PFP) to dynamically adjust the reputation of threatener, and store restricted threatener and their reputation on the blockchain, thus providing data support to each AS to take restriction measures. Compared with information sharing based on a centralized database, the ATTRM6 mechanism can accomplish more reliable sharing. Experimental results show that the ATTRM6 mechanism has low overhead and can effectively perform IPv6 address traceback and threatener restriction.
The education management model refers to the system and processes that colleges and universities use to manage and oversee their academic programs and operations. However, with the advent of digital technologies, there has been a growing trend towards the Internet+ college education management model, which integrates digital technologies into all aspects of college education management. This model includes the use of online learning platforms and tools, such as learning management systems (LMS), to deliver courses and manage student progress. It also includes the use of digital technologies for administrative tasks such as admissions, enrolment, and financial aid. However, the educational management model is subjected to the challenge of security for educational data management. Hence, this paper constructed a secure framework model of the Ethereum SDN Cloud Architecture (ESDNarc). The ESDNarc model uses the Software-defined Network (SDN) for the decentralized management of the network, secure transactions, and improved efficiency. The ESDNarch model incorporates the SDN with the cryptography scheme the secure the data. The constructed model uses the double-hashing Elliptical Curve Cryptography (DHECC) for the data stored in the Ethereum blockchain. The performance of the constructed model is evaluated with the KDD data set. Simulation analysis stated that ESDNarch significantly increases the data security in the cloud model for the attacks in the network.
Engin Zeydan, Jorge Baranda, Josep Mangues‐Bafalluy, Yekta Türk
In the coming years, blockchain technologies will be used in a variety of industries, including telecommunications. In this article, due to strict governance of telecommunication infrastructure, we propose a blockchain supported architecture, based on a permissioned distributed ledger (PDL) scheme, for a network management and orchestration platform. The main goal is to create a trusted environment for multiple-stakeholders, such as Cloud Service Providers (CSPs), a Mobile Network Operator (MNO), Vertical Service Providers (SPs), Legal and Regulation Authorities, and Responsible Ministry so that the life cycle of automated vertical network services (e.g., instantiation, scaling, termination, and migration/reallocation) can be managed securely and transparently in a multi-cloud and multi-domain environment. The proposed approach is also validated with an experimental Industry 4.0 scenario using the Quorum blockchain network (BCN) to measure various performance metrics (e.g., number of transactions and blocks, and time to write) of various service orchestrator (SO)-related instantiation metrics. At the end of the article, we present the main discussions on the evaluation results and existing standardization efforts for the convergence of BCN, Management and Orchestration (MANO), and network services for a given telecommunication infrastructure.
The Metaverse is gaining attention among academics as maturing technologies empower the promises and envisagements of a multi-purpose, integrated virtual environment. An interactive and immersive socialization experience between people is one of the promises of the Metaverse. In spite of the rapid advancements in current technologies, the computation required for a smooth, seamless and immersive socialization experience in the Metaverse is overbearing, and the accumulated user experience is essential to be considered. The computation burden calls for computation offloading, where the integration of virtual and physical world scenes is offloaded to an edge server. This paper introduces a novel Quality-of-Service (QoS) model for the accumulated experience in multi-user socialization on a multichannel wireless network. This QoS model utilizes deep reinforcement learning approaches to find the near-optimal channel resource allocation. Comprehensive experiments demonstrate that the adoption of the QoS model enhances the overall socialization experience.
Ronan D. Mendonça, Ericksulino Moura, Glauber Dias Gonçalves, Alex Borges Vieira · 5 authors
Blockchain é uma tecnologia que amplia a segurança nas relações entre organizações via o registro auditável e descentralizado de transações. Notadamente, há uma crescente atenção por aplicações que utilizam essa tecnologia. Entretanto, a eficiência e custo de tais aplicações pode ser influenciada pela rede blockchain utilizada. De fato, a escolha da rede impacta nas qualidades não funcionais das aplicações, em especial desempenho (e.g., em relação a taxa de transações efetivadas) e custo. Este artigo investiga o impacto no desempenho e custo da infraestrutura de rede blockchain para lidar com uma determinada carga de trabalho. Primeiramente, este artigo propõe um modelo de arquitetura de rede comum entre a rede pública Ethereum e permissionada Hyperledger Fabric com base em recursos por nó par da rede blockchain. A seguir, avalia-se o custo por transação para aplicações nessa arquitetura considerando latências e custos mínimos para os pares da rede, em função da carga de trabalho. Os experimentos realizados nas plataformas mais populares para redes blockchain, Ethereum e Hyperledger Fabric, mostram os limites de escalabilidade dessas plataformas e os seus compromissos entre custo e desempenho no projeto de aplicações baseadas em blockchain.
Physical terminals provide network services to upper-layer applications, but their limited memory and processing power make it challenging to perform security updates and patches, leaving them vulnerable to known security threats. Attackers can exploit these weaknesses to control the terminals and attack the network. To restrict unauthorized access to the network and its resources, appropriate access control mechanisms are necessary. In this paper, we propose a fine-grained access control method based on smart contracts (FACSC) for terminals in software-defined networking (SDN). FACSC utilizes the attribute-based access control (ABAC) model to achieve fine-grained control over terminal access networks. To ensure the security and reliability of access control policies and terminal-related attribute information, we utilize smart contract technology to implement the ABAC model. Furthermore, we leverage the programming protocol-independent packet processor (P4) to filter and forward packets in the data plane based on the packet option field, enabling rapid terminal access. Experimental results show that our proposed method achieves fine-grained secure authentication of terminals in SDN networks with a low authentication processing overhead.
Jaime Fúster de la Fuente, Álvaro Pendás-Recondo, Leon Wong, Paul Harvey
Operation and management of telecommunication networks are increasingly difficult with the demands and behaviors of users exceeding the capacity of network engineers to keep pace. This has led to increased automation of the network, enabled by various forms of intelligent software. One such proposal from the ITU-T Focus Group on Autonomous Networks (standardization group) is an architecture to achieve self-driven automation (i.e. autonomy) of network operation, whereby technology from different operators and third parties is self-assembled and deployed in production networks. This raises questions and challenges regarding transparency, auditability, and trust while maintaining interoperability.This work presents an initial study of a distributed and decentralized marketplace to bring transparent and auditable trust to the proposed architecture without sacrificing interoperable functionality. We demonstrated this by our proof of concept implementation of both the proposed architecture and marketplace based on the combination of Ethereum and IPFS.
Luis Velasco, Marc Ruiz, Pol González, Vincent Lefèbvre · 6 authors
Multi-agent systems (MAS) have been proposed as an alternative to traditional centralized control for near real-time service control. However, MAS also show a distributed attack surface. To overcome their software higher security exposure, we combine a set of scalable techniques fostering enhanced security applied on individual agents and their communications. Specifically, the proposed solution combines: <em>i</em>) binary hardening with secure execution monitoring; <em>ii</em>) distributed ledger technologies for non-real-time MAS management; and <em>iii</em>) VXLAN and encrypted communications for near real-time MAS operation. The solution is designed not only to provide strong security to the MAS, but also to minimize any functional overhead.
In the industrial Internet of things (IIoT), various applications generate a large number of interactions and are vulnerable to various attacks, which are difficult to be monitored in a sophisticated way by traditional network architectures. Therefore, deploying software-defined network (SDN) in IIoT is essential to defend against various attacks. However, SDN has a draw-back: there is a security problem of distributed denial-of-service (DDoS) attacks at the control layer. This paper proposes an effective solution: DDoS detection within the domain using tri-entropy in information theory. The detected attacks are then uploaded to a smart contract in the blockchain, so that the attacks can be quickly cut off even if the same attack occurs in different domains. Experimental validation was conducted under different attack strengths and multiple identical attacks, and the results show that the method has better detection ability under different attack strengths and can quickly block the same attacks.
Farhana Javed, Josep Mangues‐Bafalluy, Engin Zeydan
This poster presents a use case for smart contract-based inter-provider agreements and Service Level Agreement (SLA) monitoring for 6G networks. We use chainlink oracle and InterPlanetary File System (IPFS) to monitor SLA data logs. We also provide experimental evaluations of two approaches: raw data log access in IPFS and chainlink-based log access. To understand the performance and feasibility of the proposed approaches on a public blockchain, the proposed framework is deployed on the Ethereum and Polygon testnets to measure the cost and latency for both approaches. We measure the latency as well as the total cost for comparison purposes. The maximum cost observed for the first approach is ≈ 1.4 USD, and the maximum latency observed with the first approach is ≈4 seconds in the Polygon testnet and 12 ~ 14 seconds in the Ethereum testnet. However, the second approach's latency is 30 ~ 60 seconds.
Rihab Jmal, Walid Ghabri, Ramzi Guesmi, Badr M. Alshammari · 6 authors
By bringing smart and advanced solutions, the Internet of Things (IoT) has opened up new dimensions of innovative services and processing power for contemporary living standards. IoT has a wide range of devices and communication entities as a result of the widespread applications of these services, making network management a challenging task. Therefore, it is critical to redesign the IoT network’s management. The inherent programmability and centralized capabilities of software-defined networking (SDN) make network management simpler, enable network abstraction, make network evolution easier, and have the potential to handle the IoT network. However, security issues still present the IoT dilemma. Distributed Denial of Service (DDoS) attacks are among the most significant security threats in IoT systems. This paper studies in-depth DDoS attacks in IoT and in SDN. A review of different detection and mitigation techniques based on SDN, blockchain and machine learning models is conducted. A holistic, secure IoT system is proposed on the basis of SDN with multicontrollers. Blockchain is considered to guarantee security in distributed SDN-IoT networks and ANN to improve the detection and mitigation process.
Michael G. Xevgenis, Dimitrios G. Kogias, Panagiotis Karkazis, Helen C. Leligou
Undoubtedly, we are witnessing a new era of computer networks that aspire to support modern demanding applications by providing the highest Quality of Experience (QoE) to the end user. Next Generations Networks (NGNs) ensure that characteristics such as ultra-low latency, high availability and wide service coverage can be met across the network regardless of the network infrastructure ownership. To accomplish that, beyond the necessary improvements in the radio propagation field, changes have been made in the core network functions which are now characterized as programmable, and software defined. Software Defined Networks (SDNs) and Network Function Virtualization (NFV) are the keystones of the NGNs flexibility. The high expectations of NGNs’ performance and the continuous changes in the network conditions lead to the development of new network management frameworks that add elasticity and dynamicity and minimize human intervention. ETSI (the European Standards Organization) presents the Zero-touch Service Management (ZSM) framework that uses hyped technologies such as Artificial Intelligence (AI) and Machine Learning (ML) to achieve full end-to-end automation of the network services’ management across one or many different domains. Focusing on multi-domain network service management, there are several security issues identified by the standardization team which mostly derive from the lack of trust among network providers. In the present research, we explore the suitability of blockchain technology adoption for facing these security issues. Blockchain technology inherently addresses security in trustless environments such as the infrastructures defined by the ZSM team. Our contribution is three-fold: (a) we define the architecture of a multi-domain network infrastructure that adopts the ZSM approach and integrates blockchain functionality, (b) we explore the adoption of different blockchain and distributed ledger technologies (DLT) approaches to address ZSM security needs and (c) we provide guidelines to prospective solution designers/implementers on the detailed requirements that this solution has to meet to maximize the offered value.