Quarantining Malicious IoT Devices in Intelligent Sliced Mobile Networks

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Candal-Ventureira, David, Fondo-Ferreiro, Pablo, Gil-Castiñeira, Felipe, González-Castaño, Francisco Javier
Natura: Preprint
Pubblicazione: 2024
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866929295079768064
author Candal-Ventureira, David
Fondo-Ferreiro, Pablo
Gil-Castiñeira, Felipe
González-Castaño, Francisco Javier
author_facet Candal-Ventureira, David
Fondo-Ferreiro, Pablo
Gil-Castiñeira, Felipe
González-Castaño, Francisco Javier
contents The unstoppable adoption of the Internet of Things (IoT) is driven by the deployment of new services that require continuous capture of information from huge populations of sensors, or actuating over a myriad of "smart" objects. Accordingly, next generation networks are being designed to support such massive numbers of devices and connections. For example, the 3rd Generation Partnership Project (3GPP) is designing the different 5G releases specifically with IoT in mind. Nevertheless, from a security perspective this scenario is a potential nightmare: the attack surface becomes wider and many IoT nodes do not have enough resources to support advanced security protocols. In fact, security is rarely a priority in their design. Thus, including network-level mechanisms for preventing attacks from malware-infected IoT devices is mandatory to avert further damage. In this paper, we propose a novel Software-Defined Networking (SDN)-based architecture to identify suspicious nodes in 4G or 5G networks and redirect their traffic to a secondary network slice where traffic is analyzed in depth before allowing it reaching its destination. The architecture can be easily integrated in any existing deployment due to its interoperability. By following this approach, we can detect potential threats at an early stage and limit the damage by Distributed Denial of Service (DDoS) attacks originated in IoT devices.
format Preprint
id arxiv_https___arxiv_org_abs_2403_19731
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Quarantining Malicious IoT Devices in Intelligent Sliced Mobile Networks
Candal-Ventureira, David
Fondo-Ferreiro, Pablo
Gil-Castiñeira, Felipe
González-Castaño, Francisco Javier
Networking and Internet Architecture
The unstoppable adoption of the Internet of Things (IoT) is driven by the deployment of new services that require continuous capture of information from huge populations of sensors, or actuating over a myriad of "smart" objects. Accordingly, next generation networks are being designed to support such massive numbers of devices and connections. For example, the 3rd Generation Partnership Project (3GPP) is designing the different 5G releases specifically with IoT in mind. Nevertheless, from a security perspective this scenario is a potential nightmare: the attack surface becomes wider and many IoT nodes do not have enough resources to support advanced security protocols. In fact, security is rarely a priority in their design. Thus, including network-level mechanisms for preventing attacks from malware-infected IoT devices is mandatory to avert further damage. In this paper, we propose a novel Software-Defined Networking (SDN)-based architecture to identify suspicious nodes in 4G or 5G networks and redirect their traffic to a secondary network slice where traffic is analyzed in depth before allowing it reaching its destination. The architecture can be easily integrated in any existing deployment due to its interoperability. By following this approach, we can detect potential threats at an early stage and limit the damage by Distributed Denial of Service (DDoS) attacks originated in IoT devices.
title Quarantining Malicious IoT Devices in Intelligent Sliced Mobile Networks
topic Networking and Internet Architecture
url https://arxiv.org/abs/2403.19731