Software Defined Networking (SDN) is being extensively adopted by researchers and enterprise networks due to its feature of decoupling data and control planes from network device which enables them to implement new networking ideas. Communication between data and control planes faces various security issues where many users in data plane approach controller device in control plane to gain networking policies. In this paper, we proposed an efficient Zero-knowledge proof based identification scheme for securing SDN controller during data and control plane communication. This scheme ensures that only users who prove their knowledge about secrecy without revealing actual secret or any other information about it can communicate with controller. The computation cost was calculated to validate efficiency of the proposed work and compared with scheme that works in the basis of Kerberos authentication protocol.
Evangelos Pournaras, Srivatsan Yadhunathan, Ada Diaconescu
Structure plays a key role in learning performance. In centralized computational systems, hyperparameter optimization and regularization techniques such as dropout are computational means to enhance learning performance by adjusting the deep hierarchical structure. However, in decentralized deep learning by the Internet of Things, the structure is an actual network of autonomous interconnected devices such as smart phones that interact via complex network protocols. Self-adaptation of the learning structure is a challenge. Uncertainties such as network latency, node and link failures or even bottlenecks by limited processing capacity and energy availability can significantly downgrade learning performance. Network self-organization and self-management is complex, while it requires additional computational and network resources that hinder the feasibility of decentralized deep learning. In contrast, this paper introduces a self-adaptive learning approach based on holarchic learning structures for exploring, mitigating and boosting learning performance in distributed environments with uncertainties. A large-scale performance analysis with 864,000 experiments fed with synthetic and real-world data from smart grid and smart city pilot projects confirm the cost-effectiveness of holarchic structures for decentralized deep learning.
In Software-Defined Networking (SDN), Northbound Interface provides APIs, which allow network applications to communicate with SDN controllers. However, a malicious application can access to SDN controller and perform illegal activities via these APIs. Although some studies proposed AAA (Authentication, Authorization, Accounting) systems to protect SDN controllers from malicious applications, their proposed systems also exist several limitations. Attackers can compromise a system, then modify its database or files to gain higher privileges. This system can be taken down because of Single Point of Failure threat. To enhance security for the Northbound interface, we propose a novel system using blockchain, namely BlockAS. It is used to authenticate, authorize and monitor accessing critical controller resources from applications. Specifically, BlockAS leverages blockchain features to maintain the immutability and decentralization of credential data. Our proposed system has five key properties: immutability of database, decentralization, authentication, authorization, and accounting to enhance security for SDN controller and its offered services.
The new network paradigm of Software Defined Networking (SDN) has been widely adopted. Due to its inherent advantages, SDN has been widely used in various network fields such as data centers, WAN, enterprise, Optical Networks and energy Internet. Among them, SDN-based energy Internet systems are receiving more and more attention. But at the same time, some problems and challenges are gradually becoming more prominent. The SDN-based energy Internet is a distributed architecture for renewable energy, so the traditional centralized electric energy trading model will no longer apply. The blockchain has been rapidly developed and applied in various domains by virtue of its decentralization, coordinated autonomy, and non-tamperability. We propose an SDN-based energy Internet distributed energy trading scheme supported by blockchain technology. The proposed scheme achieves a reasonable match of the transaction objects under the premise of protecting privacy. Finally, we conducted a comprehensive, systematic security and applicability analysis of the proposed solution, further confirming that the system meets our design goals.
Eder J. Scheid, Manuel Keller, Muriel Figueredo Franco, Burkhard Stiller
Current projects applying blockchain technology to enhance the trust of NFV environments do not consider the VNF repository. However, the blockchain’s properties can enhance trust by allowing to verify a VNF package’s integrity without relying (a) on a Trusted Third Party (TTP) for remote attestation or (b) a secure database. This paper presents BUNKER , a Blockchain-based trUsted VNF packagE Repository, intended to be integrated with traditional database-based package verification environments, acting as a trusted repository containing VNF package information. Moreover, BUNKER allows users to acquire VNFs without the need of a TTP using an Ethereum Smart Contract (SC). The SC automatically transfers license fees to the vendor once a VNF is acquired, and sends the VNF package’s link to the buyer before verifying its integrity.
Distributed Denial of Service (DDoS) attacks have two defense perspectives firstly, to defend your network, resources and other information assets from this disastrous attack. Secondly, to prevent your network to be the part of botnet (botforce) bondage to launch attacks on other networks and resources mainly be controlled from a control center. This work focuses on the development of a botnet prevention system for Internet of Things (IoT) that uses the benefits of both Software Defined Networking (SDN) and Distributed Blockchain (DBC). We simulate and analyze that using blockchain and SDN, how can detect and mitigate botnets and prevent our devices to play into the hands of attackers.
This paper presents a blockchain-based high-efficiency security strategy with blockchain ledger-based recovery algorithm for software-defined optical networks. Numerical results show the proposed strategy has less recovery latency and superior network performances.
A Potential solution for solving forensic is the use of blockchain in software-defined networking (SDN). The blockchain is a distributed peer-to-peer network that can be utilized on SDN-based Internet of Things (IoT) environments for security provisioning. Hence, to meet some challenges in digital forensics such as data integrity, evidence deletion or alteration, blockchain is used. However, some problems such as poor attack detection and slow processing existed in previous works. To address these issues, an efficient forensics architecture is proposed in SDN-IoT that establishes the Chain of Custody (CoC) in blockchain technology. The proposed SDN-based IoT architecture is initiated with flow table rules on switches for the three different traffics Voice over Internet Protocol (VoIP), File Transfer Protocol (FTP), and Hyper Text Transfer Protocol (HTTP). In this work, overloaded switches migrate the packets to nearby switches to balance the packet flow. The packets disobeying flow rules will be discarded by switches. The blockchain-based distributed controller in this forensic architecture is designed to use the Linear Homomorphic Signature (LHS) algorithm for validating users. Each controller is fed with a classifier that uses the Neuro Multi-fuzzy to classify malicious packets based on packet features. The logs of events are used and stored on the blockchain in the proposed SDN-IoT architecture. We evaluated the performance of our forensic architecture and compared it to the existing model using various performance measures. Our evaluation results demonstrate performance improvement by reducing delay, response time and processing time, increasing throughput, accuracy, and security parameters.
Jordi Paillissé, Jordi Subira, Albert López, Alberto Rodríguez-Natal · 7 authors
The specification and enforcement of network-wide policies in a single administrative domain is common in today's networks and considered as already resolved. However, this is not the case for multi-administrative domains, e.g. among different enterprises. In such situation, new problems arise that challenge classical solutions such as PKIs, which suffer from scalability and granularity concerns. In this paper, we present an extension to Group-Based Policy -- a widely used network policy language -- for the aforementioned scenario. To do so, we take advantage of a permissioned blockchain implementation (Hyperledger Fabric) to distribute access control policies in a secure and auditable manner, preserving at the same time the independence of each organization. Network administrators specify polices that are rendered into blockchain transactions. A LISP control plane (RFC 6830) allows routers performing the access control to query the blockchain for authorizations. We have implemented an end-to-end experimental prototype and evaluated it in terms of scalability and network latency.
Bitcoin has a low transaction throughput. In order to allow for an increase of this throughput without increasing orphan blocks, decreasing the block propagation time is important. One of the techniques to improve its block propagation time is to utilize relay networks. However, the effects of utilizing relay networks is not apparent. Existing studies and measurements on relay networks have not focused on the effect of relay networks on the individual miners. Moreover, the relation between the degree of the effect and relay network utilization rate is unknown. Herein, we performed simulations while finely changing the proportion of nodes utilizing a relay network. Moreover we quantitatively evaluated the effect of relay networks on the entire Bitcoin network and individual miners. Results show that the propagation time decrease to approximately 77% of the original value if the utilization rate is set to 3%. This rate is close to the actual utilization rate of relay network "Falcon". We also found that the probability of blocks created by utilizing nodes to become orphan blocks is surprisingly smaller than that of the non-utilizing nodes. Even in the worst case, the value of utilizing nodes is 15% of the value of non-utilizing nodes.
Jan 1, 2019·Proceedings of the VIth International Workshop 'Critical Infrastructures: Contingency Management, Intelligent, Agent-Based, Cloud Computing and Cyber Security' (IWCI 2019)
Konstantin Mironov, Sergey Trishin, Amir Makhmutov, Vadim Kartak · 5 authors
In this article we consider tasks related to ensuring the integrity and availability of information in the Internet of Things (IoT) sphere. Such systems include sensors and similar devices, which are the sources of data, access points, which transmit data from sensors to the Internet and servers, which store received data and grant access to users. When storing data on a server and providing access to it, it is necessary to ensure its integrity and availability to users. To this end, it is proposed to apply a distributed ledger technology (DLT). One of the applications of DLT for data protection is energetics. Here we consider a system for processing and storing data on the production and consumption of electricity in a decentralized power grid. A review of currently existing projects related to the use of distributed ledger technologies in the energy sector is carried out. An important obstacle to the use of DLT in the IoT is the contradiction between, on the one hand, high memory computational requirements of the DLT, and, on the other hand, limited resources of IoT nodes. Further research directions are proposed that are associated with overcoming this obstacle in applying distributed ledger technologies in the energetics.
Zakaria Abou El Houda, Abdelhakim Hafid, Lyes Khoukhi
With the exponential growth in the number of insecure devices, the impact of Distributed Denial-of-Service (DDoS) attacks is growing rapidly. Existing DDoS mitigation schemes are facing obstacles due to low flexibility, lack of resources, and high cost. The new emerging technologies, such as blockchain, introduce new opportunities for low-cost, efficient and flexible DDoS attacks mitigation across multiple domains. In this paper, we propose a blockchain-based approach, called Cochain-SC, which combines two levels of mitigation, intra-domain and inter-domain DDoS mitigation. For intra-domain, we propose an effective DDoS mitigation method in the context of software defined networks (SDN); it consists of three schemes: (1) Intra Entropy-based scheme (I-ES) to measure, using sFlow, the randomness of data inside the domain; (2) Intra Bayes-based scheme (I-BS) to classify, based on entropy values, illegitimate flows; and (3) Intra-domain Mitigation (I-DM) scheme to effectively mitigate illegitimate flows inside the domain. For inter-domain, we propose a collaborative DDoS mitigation scheme based on blockchain; it uses the concept of smart contracts (i.e., Ethereum's smart contracts) to facilitate the collaboration among SDN-based domains (i.e., Autonomous System: AS) to mitigate DDoS attacks. For this aim, we design a novel and secure scheme that allows multiple SDN-based domains to securely collaborate and transfer attack information in a decentralized manner. Combining intra- and inter-domain DDoS mitigation, Cochain-SC allows an efficient mitigation along the path of an ongoing attack and an effective mitigation near the origin of the attack. This allows reducing the enormous cost of forwarding packets, across multiple domains, which consist mostly of useless amplified attack traffic. To the best of our knowledge, Cochain-SC is the first scheme that proposes to deal with both intra-domain and inter-domain DDoS attacks mitigation combining SDN, blockchain and smart contract. The implementation of Cochain-SC is deployed on Ethereum official test network Ropsten. Moreover, we conducted extensive experiments to evaluate our proposed approach; the experimental results show that Cochain-SC achieves flexibility, efficiency, security, cost effectiveness, and high accuracy in detecting illegitimate flows, making it a promising approach to mitigate DDoS attacks.
Yuma Sakakibara, Yuta Tokusashi, Shin Morishima, Hiroki Matsutani
Blockchain is core technology for cryptocurrency and it is possible to become fundamental platform for industry and business. Especially, a blockchain-based digital asset transfer system using Internet of Things (IoT) products has recently been considered as a new practical platform, but the protocol limits performance. Previous research has improved performance by proposing new protocols, but further improvement is necessary for dealing with increasing transactions via IoT products. Therefore, we propose an in-Network Interface Card (in-NIC) processing approach using a Field Programmable Gate Array (FPGA) to improve performance of a blockchain-based transfer system. To be more concrete, we design and implement a prototype NIC with a key-value data store written in a P4 language on the FPGA that has four 10Gigabit Ethernet (10GbE) network interfaces. The prototype system supports frequently-used commands (CREATE, ISSUE, TRANSFER and REFER) for transferring digital asset. It reduces time for processing a kernel network protocol stack and accessing the data store. In fact, we measured throughput and latency of our prototype system compared to those of a blockchain software application. As a result, we found that our solution is able to obtain throughput 6.04 times higher on average and latency 15.4 times lower on average for all typical blockchain operations.
Zakaria Abou El Houda, Lyes Khoukhi, Abdelhakim Hafid
Nowadays, blockchain is seen as one of the main technological innovations. Many applications can rely on the blockchain to secure their exchanges. However, applications with private interest cannot rely on public blockchains. First, in a public blockchain, anyone can read the whole data of the blockchain. Second, anyone can participate to the "consensus process"; the process for determining the validity of each transaction. Consortium and fully private blockchains aim to combine forcefulness of blockchains with controlled consensus process and stricter permissions for deploying a node and joining the blockchain network. In both consortium and fully private blockchains, the number of peers on the blockchain network is very small in comparison with public blockchain. Nonetheless, by targeting the nodes of blockchains, an attacker can easily manage the whole blockchain and takes control of the consensus process to validate his illegitimate transactions. In this paper, to defend blockchain nodes from DNS amplification attacks, we propose a scalable and proactive solution in the context of software defined networks (SDN), named ChainSecure. ChainSecure consists of 3 schemes: (1) StateMap, a novel stateful mapping scheme (SMS) to perform a mapping one-to-one between DNS request and response; (2) Entropy calculation scheme (ECS) to measure the disorder / randomness of data using sFlow in order to detect illegitimate flows; (3) DNS DDoS Mitigation (DDM) module to effectively mitigate illegitimate DNS requests. The experimental results show that ChainSecure protects blockchain nodes and can detect/mitigate the attack quickly to achieve high accuracy in detecting illegitimate DNS traffic making it a promising solution to protect blockchain nodes from DNS amplification attacks.
Pedro Marcos, Marco Chiesa, Lucas Fernando Müller, Pradeeban Kathiravelu · 7 authors
Autonomous Systems (ASes) can reach hundreds of networks via Internet eXchange Points (IXPs), allowing improvements in traffic delivery performance and competitiveness. Despite the benefits, any pair of ASes needs first to agree on exchanging traffic. By surveying 100+ network operators, we discovered that most interconnection agreements are established through ad-hoc and lengthy processes heavily influenced by personal relationships and brand image. As such, ASes prefer long-term agreements at the expense of a potential mismatch between actual delivery performance and current traffic dynamics. ASes also miss interconnection opportunities due to trust reasons. To improve wide-area traffic delivery performance, we propose Dynam-IX, a framework that allows operators to build trust cooperatively and implement traffic engineering policies to exploit the rich interconnection opportunities at IXPs quickly. Dynam-IX offers a protocol to automate the interconnection process, an intent abstraction to express interconnection policies, a legal framework to digitally handle contracts, and a distributed tamper-proof ledger to create trust among ASes. We build and evaluate a Dynam-IX prototype and show that an AS can establish tens of agreements per minute with negligible overhead for ASes and IXPs.
The digital payment system that uses cryptocurrency, such as Bitcoin, is a distributed ledger working on a peer-to-peer network. We present a method to make a scale-free network for such applications. Using some biased physical quantities that are observable in sites, we can make the scale-free network through processes of cooperating distributed sites. Each node only proposes connecting to the more attractive node among randomly known nodes. The candidate node that is found by each node agrees to set two-way links if the requesting node is more attractive than the old node that is already connected. Once they establish the new bidirectional relationship, they, respectively, remove the outgoing link to the less attractive node. We analytically calculate the connectivity distribution and show that the scaling exponent is 2.5. By Monte Carlo simulations, we confirm that a power law distribution of the scaling exponent 2.5 describes the degree distribution of the topology.
Chao Qiu, F. Richard Yu, Haipeng Yao, Chunxiao Jiang · 6 authors
With the developments of communication technologies and smart manufacturing, Industrial Internet of Things (IIoT) has emerged. Software-defined networking (SDN), a promising paradigm shift, has provided a viable way to manage IIoT dynamically, called software-defined IIoT (SDIIoT). In SDIIoT, lots of data and flows are generated by industrial devices, where a physically distributed but logically centralized control plane is necessary. However, one of the most intractable problems is how to reach consensus among multiple controllers under complex industrial environments. In this paper, we propose a blockchain (BC)-based consensus protocol in SDIIoT, along with detailed consensus steps and theoretical analysis, where BC works as a trusted third party to collect and synchronize network-wide views between different SDN controllers. Specially, it is a permissioned BC. In order to improve the throughput of this BC-based SDIIoT, we jointly consider the trust features of BC nodes and controllers, as well as the computational capability of the BC system. Accordingly, we formulate view change, access selection, and computational resources allocation as a joint optimization problem. We describe this problem as a Markov decision process by defining state space, action space, and reward function. Due to the fact that it is difficult to solve this joint problem by traditional methods, we propose a novel dueling deep Q-learning approach. Simulation results are presented to show the effectiveness of our proposed scheme.
Despite growing adoption of cryptocurrencies, making fast payments at scale remains a challenge. Payment channel networks (PCNs) such as the Lightning Network have emerged as a viable scaling solution. However, completing payments on PCNs is challenging: payments must be routed on paths with sufficient funds. As payments flow over a single channel (link) in the same direction, the channel eventually becomes depleted and cannot support further payments in that direction; hence, naive routing schemes like shortest-path routing can deplete key payment channels and paralyze the system. Today's PCNs also route payments atomically, worsening the problem. In this paper, we present Spider, a routing solution that "packetizes" transactions and uses a multi-path transport protocol to achieve high-throughput routing in PCNs. Packetization allows Spider to complete even large transactions on low-capacity payment channels over time, while the multi-path congestion control protocol ensures balanced utilization of channels and fairness across flows. Extensive simulations comparing Spider with state-of-the-art approaches shows that Spider requires less than 25% of the funds to successfully route over 95% of transactions on balanced traffic demands, and offloads 4x more transactions onto the PCN on imbalanced demands.
Maria Apostolaki, Gian Marti, Jan Müller, Laurent Vanbever
Routing attacks remain practically effective in the Internet today as existing countermeasures either fail to provide protection guarantees or are not easily deployable. Blockchain systems are particularly vulnerable to such attacks as they rely on Internet-wide communication to reach consensus. In particular, Bitcoin -the most widely-used cryptocurrency- can be split in half by any AS-level adversary using BGP hijacking. In this paper, we present SABRE, a secure and scalable Bitcoin relay network which relays blocks worldwide through a set of connections that are resilient to routing attacks. SABRE runs alongside the existing peer-to-peer network and is easily deployable. As a critical system, SABRE design is highly resilient and can efficiently handle high bandwidth loads, including Denial of Service attacks. We built SABRE around two key technical insights. First, we leverage fundamental properties of inter-domain routing (BGP) policies to host relay nodes: (i) in locations that are inherently protected against routing attacks; and (ii) on paths that are economically preferred by the majority of Bitcoin clients. These properties are generic and can be used to protect other Blockchain-based systems. Second, we leverage the fact that relaying blocks is communication-heavy, not computation-heavy. This enables us to offload most of the relay operations to programmable network hardware (using the P4 programming language). Thanks to this hardware/software co-design, SABRE nodes operate seamlessly under high load while mitigating the effects of malicious clients. We present a complete implementation of SABRE together with an extensive evaluation. Our results demonstrate that SABRE is effective at securing Bitcoin against routing attacks, even with deployments as small as 6 nodes.