IoT-NetSec: Policy-Based IoT Network Security Using OpenFlow
Mehdi Nobakht, Craig Russell, Wen Song Hu, Aruna Prasad Seneviratne · 2019
The increasingly widespread adoption of the Internet of Things (IoT) has resulted in concerns about IoT security. Recently, there have been proposals to leverage software-defined networking (SDN) to augment IoT device security with network-level measurements. We argue that existing general-purpose security solutions using SDN are impractical for supporting today's home and corporate networks due to the high volume and rates of network traffic, differences in characteristics of IoT systems and computer networks, and limited resources in underlying network switches. To this end we propose IoT-NetSec, a framework that enables policy-based and fine-grained traffic monitoring of the network segments that include only IoT devices. We describe a prototype implementation and its integration with an SDN controller. The prototype implementation and simulations with three network service attacks (port scanning, SYN DoS Flooding and smurf DDoS) demonstrate IoT-NetSec feasibility in a network of real IoT devices.