Mehrdad Hajizadeh, Nima Afraz, Marco Ruffini, Thomas Bauschert
The legacy security defense mechanisms cannot resist where emerging sophisticated threats such as zero-day and malware campaigns have profoundly changed the dimensions of cyber-attacks. Recent studies indicate that cyber threat intelligence plays a crucial role in implementing proactive defense operations. It provides a knowledge-sharing platform that not only increases security awareness and readiness but also enables the collaborative defense to diminish the effectiveness of potential attacks. In this paper, we propose a secure distributed model to facilitate cyber threat intelligence sharing among diverse participants. The proposed model uses blockchain technology to assure tamper-proof record-keeping and smart contracts to guarantee immutable logic. We use an open-source permissioned blockchain platform, Hyperledger Fabric, to implement the blockchain application. We also utilize the flexibility and management capabilities of Software-Defined Networking to be integrated with the proposed sharing platform to enhance defense perspectives against threats in the system. In the end, collaborative DDoS attack mitigation is taken as a case study to demonstrate our approach.
Today, management and orchestration are considered prime components of the new network management layer. Multi-domain orchestration has helped in simplifying infrastructural operations and enables better scaling and faster deployment of network services. However, resource provisioning considering network optimization and fulfillment of multi-constraint quality of service (QoS) is still a major concern. In this article, an architecture comprising multi-domain edge orchestration (MDEO) entrusted by blockchain designed to solve the problem of multi-constraint QoS is proposed. A dynamic end-to-end (E2E) network slicing algorithm is devised to execute at the MDEO to enable multi-tenant on-demand network infrastructure provisioning isolation and security. The algorithm first calculates an optimum network slice topology and then instantiates the involved virtual network functions. Based on multi-constraint QoS, it fulfills the E2E slice request. Blockchain is deployed to ensure trustworthiness between different telecom operators, introduce transparency and to automate the fulfillment of service-level agreements through smart contracts. In addition, an experimental simulation of the system is performed and the burst and response times of the proposed framework are analyzed using different distributions. The data in both cases demonstrates a lognormal distributed behavior.
Jiejun Hu, Martin J. Reed, Mays Al-Naday, Nikolaos Thomos
The Internet of Things (IoT) connected by Software Defined Networking (SDN) promises to bring great benefits to cyber-physical systems. However, the increased attack surface offered by the growing number of connected vulnerable devices and complex nature of SDN control plane applications could overturn the huge benefits of such a system. This paper addresses the vulnerability of some unspecified security flaw in the SDN control plane application (such as a zero-day software vulnerability) which can be exploited to insert malicious flow rules in the switch that do not match network policies. Specifically, we propose a blockchain-as-a-service (BaaS) based framework that supports switch flow verification and insertion; and additionally provides straightforward deployment of blockchain technology within an existing SDN infrastructure. While use of an external BaaS brings straightforward deployment, it obscures knowledge of the blockchain agents who are responsible for flow conformance testing through a smart blockchain contract, leading to potential exploitation. Thus, we design a strategy to prevent the blockchain agents from acting arbitrarily, as this would result in what is termed a "moral hazard". We achieve this by developing a novel mathematical model of the fair reward scheme based on game theory. To understand the performance of our system, we evaluate our model using a Matlab based simulation framework. The simulation results demonstrate that the proposed algorithm balances the needs of the blockchain agents to maximise the overall social welfare, i.e. the sum of profits across all parties.
According to the Internet Organised Crime Threat Assessment (IOCTA) 2019 report, Bitcoin is still the currency of choice in criminal markets and as payment for cyber-related extortion attempts, such as from ransomware or a Distributed Denial-of-Service (DDoS) attack. Bitcoin is a peer-to-peer electronic cash system first proposed by Satoshi Nakamoto in 2008. By design, Bitcoin is a pseudonymous coin, meaning that users can transact with the currency without revealing their true identity. To tackle the challenge of Bitcoin-related crime, a range of deanonymization techniques have been proposed. In general, these solutions are limited by the time and resources required to predict likely transaction owners. In this paper, we propose the first software-defined network (SDN)-based Bitcoin transaction mapping solution. We analyse the Bitcoin transaction process in an SDN environment and demonstrate a deterministic approach to deanonymize users in Bitcoin's network.
Gino Carrozzo, Muhammad Shuaib Siddiqui, August Betzler, José Bonnet · 7 authors
The 5G network solutions currently standardised and deployed do not yet enable the full potential of pervasive networking and computing envisioned in 5G initial visions: network services and slices with different QoS profiles do not span multiple operators; security, trust and automation is limited. The evolution of 5G towards a truly production-level stage needs to heavily rely on automated end-to-end network operations, use of distributed Artificial Intelligence (AI) for cognitive network orchestration and management and minimal manual interventions (zero-touch automation). All these elements are key to implement highly pervasive network infrastructures. Moreover, Distributed Ledger Technologies (DLT) can be adopted to implement distributed security and trust through Smart Contracts among multiple non-trusted parties. In this paper, we propose an initial concept of a zero-touch security and trust architecture for ubiquitous computing and connectivity in 5G networks. Our architecture aims at cross-domain security & trust orchestration mechanisms by coupling DLTs with AI-driven operations and service lifecycle automation in multi-tenant and multi-stakeholder environments. Three representative use cases are identified through which we will validate the work which will be validated in the test facilities at 5GBarcelona and 5TONIC/Madrid.
A Software-Defined Networking (SDN) architecture and OpenFlow can help network administrators to provide end-to-end (E2E) Quality of Service (QoS)-guaranteed paths for flows among networks while providing finer-granular flow management along with global network view. In this context, we introduce a proof-of-concept for a blockchain-enabled QoS-based inter-Autonomous System (AS) routing framework, RoutingChain, that blends a QoS-concerned routing model and blockchain technology. This study's contributions can mainly be stated in five-fold: (i) Competitors-tailored routing coordination framework, (ii) eliminating centralized mediators while coordinating QoS-based inter-AS routing, (iii) an emerging use-case for blockchain technology in networking, (iv) reducing the number of QoS signaling-based message overhead, and (v) mitigating privacy/security concerns in inter-AS routing. Experimental results indicate that the blockchain technology can be applied on E2E QoS-based routing among networks. To the best of our knowledge, this is the first study exploiting the merits of blockchain technology to establish a novel coordination framework for QoS-enabled inter-AS routing in SDN.
Eder J. Scheid, Patrick Widmer, Bruno Rodrigues, Muriel Figueredo Franco · 5 authors
In the last years, cryptocurrencies have become increasingly popular along with their underlying distributed ledger technology, referred to as a Blockchain (BC). Nowadays, a wide variety of BC implementations are available. However, the selection of a suitable implementation for a particular application or use case is complex because it requires a technical understanding of the underlying BC implementation aspects. Therefore, this paper proposes a Controlled Natural Language (CNL) to extends existing BC selection solutions to abstract underlying implementation details. The approach allows the specification abstract high-level policies, referred to as intents, in an English-based language. The approach is inspired by previous approaches from the network management field. Moreover, a state machine-based refinement technique is proposed to refine these intents into low-level BC selection policies. The results of the performance evaluation of the prototype implementation show that the refinement process presents a minimal overhead. In addition, the perceived intuitiveness of the CNL by users was assessed in a survey. The results of the survey suggest that technical and non-technical individuals benefit from an intentbased approach equally.
Muoi Tran, Inho Choi, Gi Jun Moon, Viet-Anh Vu · 5 authors
Network adversaries, such as malicious transit autonomous systems (ASes), have been shown to be capable of partitioning the Bitcoin's peer-to-peer network via routing-level attacks; e.g., a network adversary exploits a BGP vulnerability and performs a prefix hijacking attack (viz. Apostolaki et al. [3]). Due to the nature of BGP operation, such a hijacking is globally observable and thus enables immediate detection of the attack and the identification of the perpetrator. In this paper, we present a stealthier attack, which we call the EREBUS attack, that partitions the Bitcoin network without any routing manipulations, which makes the attack undetectable to control-plane and even to data-plane detectors. The novel aspect of EREBUS is that it makes the adversary AS a natural man-in-the-middle network of all the peer connections of one or more targeted Bitcoin nodes by patiently influencing the targeted nodes' peering decision. We show that affecting the peering decision of a Bitcoin node, which is believed to be infeasible after a series of bug patches against the earlier Eclipse attack [29], is possible for the network adversary that can use abundant network address resources (e.g., spoofing millions of IP addresses in many other ASes) reliably for an extended period of time at a negligible cost. The EREBUS attack is readily available for large ASes, such as Tier-1 and large Tier-2 ASes, against the vast majority of 10K public Bitcoin nodes with only about 520 bit/s of attack traffic rate per targeted Bitcoin node and a modest (e.g., 5-6 weeks) attack execution period. The EREBUS attack can be mounted by nation-state adversaries who would be willing to execute sophisticated attack strategies patiently to compromise cryptocurrencies (e.g., control the consensus, take down a cryptocurrency, censor transactions). As the attack exploits the topological advantage of being a network adversary but not the specific vulnerabilities of Bitcoin core, no quick patches seem to be available. We discuss that some naive solutions (e.g., whitelisting, rate-limiting) are ineffective and third-party proxy solutions may worsen the Bitcoin's centralization problem. We provide some suggested modifications to the Bitcoin core and show that they effectively make the EREBUS attack significantly harder; yet, their non-trivial changes to the Bitcoin's network operation (e.g., peering dynamics, propagation delays) should be examined thoroughly before their wide deployment.
5G and Blockchain are potentially revolutionizing future technologies. 5G promises high rates and QoS to the users and blockchain guarantees a high level of trust and security among the peers. Applications that would be using 5G have varying needs in terms of speed, bandwidth, latency and various other factors. Augmented reality, self-driving vehicles and other ioT applications tend to use 5G for reliable and fast communication. To work seamlessly and securely in such scenarios a more specialized and efficient approach would be required. in this article, we have identified the specific areas where blockchain could be utilized to enhance the security and privacy of the 5G services offered to the users. The current challenges faced in deployment and upliftment of 5G and their related solutions based on blockchain are discussed. A model for Multi-Operator Network Slicing in 5G using blockchain is also presented along with 5G blockchain implementation.
Ronghua Xu, Yu Chen, Erik Blasch, Alexander Aved · 6 authors
Advancement in artificial intelligence (AI) and machine learning (ML), dynamic data driven application systems (DDDAS), and hierarchical cloud-fog-edge computing paradigm provide opportunities for enhancing multi-domain systems performance. As one example that represents multi-domain scenario, a "fly-by-feel" system utilizes DDDAS framework to support autonomous operations and improve maneuverability, safety and fuel efficiency. The DDDAS "fly-by-feel" avionics system can enhance multi-domain coordination to support domain specific operations. However, conventional enabling technologies rely on a centralized manner for data aggregation, sharing and security policy enforcement, and it incurs critical issues related to bottleneck of performance, data provenance and consistency. Inspired by the containerized microservices and blockchain technology, this paper introduces BLEM, a hybrid BLockchain-Enabled secure Microservices fabric to support decentralized, secure and efficient data fusion and multi-domain operations for avionics systems. Leveraging the fine-granularity and loose-coupling features of the microservices architecture, multidomain operations and security functionalities are decoupled into multiple containerized microservices. A hybrid blockchain fabric based on two-level committee consensus protocols is proposed to enable decentralized security architecture and support immutability, auditability and traceability for data provenience in existing multi-domain avionics system. Our evaluation results show the feasibility of the proposed BLEM mechanism to support decentralized security service and guarantee immutability, auditability and traceability for data provenience across domain boundaries.
Xiaoyuan Fu, F. Richard Yu, Jingyu Wang, Qi Qi · 5 authors
Distributed network function virtualization management and orchestration (NFV-MANO) offers a flexible way to manage and orchestrate diversified network services in large-scale Internet of vehicles (IoV). However, it is challenging to manage different services and resources in distributed NFV due to the difficulties of reliable message synchronization among multiple MANO systems. Recently, blockchain technology has emerged to solve the trust and security problems for the interconnections of multiple MANO systems. Moreover, multi-access edge computing (MEC) has become a prospective paradigm shift from the centralized cloud due to its advantages of completing tasks near users. In this work, we propose a blockchain-enabled distributed NFV framework to reach consensus among multiple MANO systems where the computation tasks of the blockchain are processed with MEC. The consensus procedures of MANO systems and blockchain nodes are explained in detail and the representation of the blockchain throughput is given. The blockchain throughput is the number of transactions a blockchain system can handle per second, which is an important evaluation indicator for the performance of a blockchain system. We make decisions for the primary node selection, the MANO system selection and the edge server selection for reaching consensus. Moreover, the blockchain throughput, the processing delay of computation tasks of blockchain and operational costs are jointly considered in the problem formulation. A dueling deep reinforcement learning approach is applied to solve this problem. Simulation results show the effectiveness of the proposed scheme.
Hao Xu, Paulo Valente Klaine, Oluwakayode Onireti, Bin Cao · 6 authors
The sixth-generation (6G) network must provide better performance than previous generations to meet the requirements of emerging services and applications, such as multi-gigabit transmission rate, higher reliability, and sub-1 ms latency and ubiquitous connection for the Internet of Everything (IoE). However, with the scarcity of spectrum resources, efficient resource management and sharing are crucial to achieving all these ambitious requirements. One possible technology to achieve all this is the blockchain. Because of its inherent properties, the blockchain has recently gained an important position, which is of great significance to the 6G network and other networks. In particular, the integration of the blockchain in 6G will enable the network to monitor and manage resource utilization and sharing efficiently. Hence, in this paper, we discuss the potentials of the blockchain for resource management and sharing in 6G using multiple application scenarios, namely, Internet of things, device-to-device communications, network slicing, and inter-domain blockchain ecosystems.
With the rise of cloud computing, data centers, and big data, the current rigid network architecture has been found to be inadequate. The modern technological demands require a flexible and easily reconfigurable network architecture. Software Defined Networking is a revolutionary concept that separates the control plane of network devices from their data plane and centralizes the control plane of all devices, facilitating the controlling of the entire network through a single portal. This helps us create flexible network architectures that can be reconfigured quickly to fit different needs. However, centralizing control leads to a Single Point of Failure and makes the network vulnerable to Denial of Service attacks, which is one of the major reasons why industries are reluctant to adopt this technology. Blockchain provides us a with a distributed ledger and a decentralized state, allowing us to create decentralized applications that run over multiple computers. This research aims to distribute the control plane of Software Defined Networks across multiple devices using blockchain. This addresses the existing security vulnerabilities of the Software Defined Network architecture such as Single Point of Failure while continuing to keep the control plane logically centralized, thereby allowing the network to be configured through a single portal. The resulting architecture has a physically distributed control plane whose logic is centralized.
Lanfranco Zanzi, Antonio Albanese, Vincenzo Sciancalepore, Xavier Costa‐Pérez
With the advent of revolutionary technologies, such as virtualization and softwarization, a novel concept for 5G networks and beyond has been unveiled: Network Slicing. Initially driven by the research community, standardization bodies as 3GPP have embraced it as a promising solution to revolutionize the traditional mobile telecommunication market by enabling new business models opportunities. Network Slicing is envisioned to open up the telecom market to new players such as Industry Verticals, e.g., automotive, smart factories, e-health, etc. Given the large number of potential new business players, dubbed as network tenants, novel solutions are required to accommodate their needs in a cost-efficient and secure manner. In this paper, we propose NSBchain, a novel network slicing brokering (NSB) solution, which leverages on the widely adopted Blockchain technology to address the new business models needs beyond traditional network sharing agreements. NSBchain defines a new entity, the Intermediate Broker (IB), which enables Infrastructure Providers (InPs) to allocate network resources to IBs through smart contracts and IBs to assign and re-distribute their resources among tenants in a secure, automated and scalable manner. We conducted an extensive performance evaluation by means of an open-source blockchain platform that proves the feasibility of our proposed framework considering a large number of tenants and two different consensus algorithms.
Bo Zhao, Yifan Liu, Xiang Li, Jiayue Li · 5 authors
The data layer devices in the Software Defined Network (SDN) play an important role in packet forwarding. However, whether the forwarding task can be efficiently completed by the node has not attracted enough attention. A method called TrustBlock is proposed in this paper, which introduces trust as a security attribute in SDN routing planning. Besides, in order to enhance the integrity and controllability of trust evaluation, the double-layer blockchain architecture is established. In the first layer, the behavior data of the node is recorded, and then the trust calculation is performed in the second layer. In the evaluation model, nodes' trust is calculated from three aspects: direct trust, indirect trust and historical trust. Firstly, from the perspective of security, blockchain is used to achieve identity authentication of nodes, after that, from the perspective of reliability, the forwarding status is used to calculate the trust value. Secondly, consensus algorithm is used to filter malicious recommendation trust value and prevent colluding attacks. Finally, the adaptive historical trust weight is designed to prevent the periodic attack. In this paper, the entropy method is used to determine the weight of each evaluation attribute, which can avoid the problem that the subjective judgment method is not adaptable to the weight setting. Simulation results show that the detection rate of the TrustBlock is up to 98.89%, which means this model can effectively identify the abnormal nodes in SDN. Moreover, it is attractive in terms of integrity and controllability.
Recently, software-defined Industrial Internet of Things (SDIIoT), the integration of software-defined networking (SDN) and Industrial Internet of Things (IIoT), has emerged. It is perceived as an effective way to manage IIoT dynamically. Aiming to improve the scalability and flexibility of SDIIoT, multi-SDN has been applied to form a physically distributed control plane to handle a large amount of data generated by industrial devices. However, as the core of multi-SDN, reaching consensus among multiple SDN controllers is a thorny issue. To meet the required design principle, this article proposes a blockchain-enabled distributed SDIIoT to synchronize local views between distinct SDN controllers and finally reach the consensus of the global view. On the other hand, both the cryptographic operations of blockchain and the noncryptographic tasks have access to the same computational resource pool of mobile edge cloud (MEC). In order to optimize the system energy efficiency, we adaptively allocate computational resources and the batch size of the block by jointly considering the trust features of SDN controllers and the resource requirements of noncryptographic operations. To implement the truly distributed manner of blockchain, we describe our problem as a partially observable Markov decision process (POMDP) and propose a novel deep reinforcement learning (DRL) approach to solve it. In the simulation results, we compare three different protocols of blockchain and show the effectiveness of our scheme in each of them.
Smart cities have emerged as a hub of intelligent applications (e.g., intelligent transportation systems, smart parking, smart homes, and e-healthcare) to provide ambient-assisted living and quality of experience to wide communities of users. The smooth execution of these applications depends on reliable data transmission between various smart devices and machines. However, the exponential increase in data traffic due to the growing dependency of end users on smart city applications has created various bottlenecks (e.g., channel congestion, manual flow configurations, limited scalability, and low flexibility) on the conventional network backbone, which can degrade the performance of any designed solution in this environment. To mitigate these challenges, SDN emerges as a powerful new technology that provides global visibility of the network by decoupling the control logic from the forwarding devices. The abstraction of network services in SDN architecture provides more flexibility for network administrators to execute various applications. In SDN architecture, the decision making process is handled by a logically centralized controller, which may have a single point of failure. An adversary/ attacker can compromise the controller using different types of attacks (e.g., eavesdropping, man-in-the middle attack, and distributed denial of service) in order to gain total control of the network by updating the flow table entries at the data plane or hindering control plane operations. Therefore, to cope with the aforementioned challenges, new strategies and solutions are required for securing the SDN-enabled network architecture at different planes and their associated interconnections. In this article, various security issues and different attack vectors are discussed along with possible solutions. To mitigate various attacks, BlockSDN, a blockchain as a service framework, for SDN is proposed. The architecture of permissioned blockchain is presented followed by two attack scenarios, 1) a malware compromised switch at the data plane and 2) distributed denial of service attack at the control plane, to demonstrate the applicability of the BlockSDN framework for various future applications. Finally, the open issues and challenges with respect to the design of blockchain solutions for SDN in smart city applications are also discussed.
Software-Defined Networking (SDN) enables flexible deployment and innovation of new networking applications by decoupling and abstracting the control and data planes. It has radically changed the concept and way of building and managing networked systems, and reduced the barriers to entry for new players in the service markets. It is considered to be a promising solution providing the scale and versatility necessary for IoT. However, SDN may also face many challenges, i.e., the centralized control plane would be a single point of failure. With the advent of blockchain technology, blockchain-based SDN has become an emerging architecture for securing a distributed network environment. Motivated by this, in this work, we summarize the generic framework of blockchain-based SDN, discuss security challenges and relevant solutions, and provide insights on the future development in this field.
Software-defined industrial network has emer-ged as an autonomous ecosystem where the network control relies on a centralized controller to provide seamless data transfer. However, the reliance on a centralized controller can lead to several challenges, such as single point of failure. An adversary can initiate a denial of service attack and limit the availability of the controller by projecting malicious or uncontrolled traffic flows. To overcome this, in this article, a deep-learning-based blockchain framework is designed for providing secure software-defined industrial network. In this framework, a blockchain mechanism is designed wherein all the switch are registered, verified (using zero-knowledge proof), and, thereafter, validated in the blockchain using a voting-based consensus mechanism. A deep Boltzmann machine based flow analyzer is deployed at the control plane to identify the anomalous switch requests. The evaluation is performed using a mininet emulator wherein the results obtained depict the superiority of the proposed framework.
Abbas Yazdinejad, Reza M. Parizi, Ali Dehghantanha, Qi Zhang · 5 authors
Internet of Things (IoT) is a disruptive technology in many aspects of our society, ranging from communications to financial transactions to national security (e.g., Internet of Battlefield / Military Things), and so on. There are long-standing challenges in IoT, such as security, comparability, energy consumption, and heterogeneity of devices. Security and energy aspects play important roles in data transmission across IoT and edge networks, due to limited energy and computing (e.g., processing and storage) resources of networked devices. Whether malicious or accidental, interference with data in an IoT network potentially has real-world consequences. In this article, we explore the potential of integrating blockchain and software-defined networking (SDN) in mitigating some of the challenges. Specifically, we propose a secure and energy-efficient blockchain-enabled architecture of SDN controllers for IoT networks using a cluster structure with a new routing protocol. The architecture uses public and private blockchains for Peer to Peer (P2P) communication between IoT devices and SDN controllers, which eliminates Proof-of-Work (POW), as well as using an efficient authentication method with the distributed trust, making the blockchain suitable for resource-constrained IoT devices. The experimental results indicate that the routing protocol based on the cluster structure has higher throughput, lower delay, and lower energy consumption than EESCFD, SMSN, AODV, AOMDV, and DSDV routing protocols. In other words, our proposed architecture is demonstrated to outperform classic blockchain.