A Cuckoo Filter-Based Anomaly Detection and Localization Mechanism for SDN-Based Multidomain IoT
摘要
Efficient and secure data forwarding is crucial for the Internet of Things (IoT). To detect and locate attacks such as injection, packet tampering, discarding, and path tampering in multi-domain IoT, it is proposed an anomaly detection and localization mechanism, CVAL-SDNs, for Software-Defined Networks based IoT. This mechanism constructs a constant-length verification label based on cuckoo filters at the ingress switch of the source domain. The label stores the fingerprints of the message authentication codes of the source domain and the subsequent domains along the path. The ingress switches of the subsequent domains perform source authentication and integrity verification on each packet by fingerprint lookup. Finally, the blockchain uses the flow identifier as the index to tally the verification results and traffic statistics from each domain and to locate the anomaly domain. Experimental results show that CVAL-SDNs can effectively detect and locate anomalies, with lower overhead loss compared to similar solutions, thus providing a cost-effective anomaly detection and localization mechanism for data forwarding in multi-domain IoT.