IPS architecture for IoT networks overlapped in SDN
Daniel Vianna Gonçalves, Francisco L. de Caldas Filho, Lucas M. C. e Martins, Guilherme de O. Kfouri, Bruno V. Dutra, Robson de Oliveira Albuquerque, Rafael T. de Sousa · 2019
The programmability resulting from the Software Defined Networking (SDN) approach facilitates the integration of the functionalities of firewalls, Intrusion Prevention Systems (IPS) and switching gear, allowing fast reconfiguration of the network in case of anomaly detection. In this paper, the proposed architecture aims to structure a distributed security measure integrating firewall, IPS, switches and a controller entity to support Internet of Things (IoT) instances, allowing the identification of anomalous behavior of IoT devices by the IPS, thus leading the SDN to block the attacks as near as possible to the sources, reducing the volume of malicious traffic and isolating the infected device from the rest of the network.