Suppr超能文献

基于区块链和随机子空间学习的用于支持软件定义网络的工业物联网安全的入侵检测系统

Blockchain and Random Subspace Learning-Based IDS for SDN-Enabled Industrial IoT Security.

作者信息

Derhab Abdelouahid, Guerroumi Mohamed, Gumaei Abdu, Maglaras Leandros, Ferrag Mohamed Amine, Mukherjee Mithun, Khan Farrukh Aslam

机构信息

Center of Excellence in Information Assurance (CoEIA), King Saud University, Riyadh 11451, Saudi Arabia.

Department of Electronics and Computer Science, USTHB University, Bab Ezzouar 16111, Algeria.

出版信息

Sensors (Basel). 2019 Jul 15;19(14):3119. doi: 10.3390/s19143119.

Abstract

The industrial control systems are facing an increasing number of sophisticated cyber attacks that can have very dangerous consequences on humans and their environments. In order to deal with these issues, novel technologies and approaches should be adopted. In this paper, we focus on the security of commands in industrial IoT against forged commands and misrouting of commands. To this end, we propose a security architecture that integrates the Blockchain and the Software-defined network (SDN) technologies. The proposed security architecture is composed of: (a) an intrusion detection system, namely RSL-KNN, which combines the Random Subspace Learning (RSL) and K-Nearest Neighbor (KNN) to defend against the forged commands, which target the industrial control process, and (b) a Blockchain-based Integrity Checking System (BICS), which can prevent the misrouting attack, which tampers with the OpenFlow rules of the SDN-enabled industrial IoT systems. We test the proposed security solution on an Industrial Control System Cyber attack Dataset and on an experimental platform combining software-defined networking and blockchain technologies. The evaluation results demonstrate the effectiveness and efficiency of the proposed security solution.

摘要

工业控制系统正面临越来越多复杂的网络攻击,这些攻击可能对人类及其环境造成非常危险的后果。为了应对这些问题,应采用新颖的技术和方法。在本文中,我们关注工业物联网中命令的安全性,以防伪造命令和命令误路由。为此,我们提出了一种集成区块链和软件定义网络(SDN)技术的安全架构。所提出的安全架构由以下部分组成:(a)一个入侵检测系统,即RSL-KNN,它结合了随机子空间学习(RSL)和K近邻(KNN)来抵御针对工业控制过程的伪造命令;(b)一个基于区块链的完整性检查系统(BICS),它可以防止篡改支持SDN的工业物联网系统的OpenFlow规则的误路由攻击。我们在工业控制系统网络攻击数据集以及结合软件定义网络和区块链技术的实验平台上测试了所提出的安全解决方案。评估结果证明了所提出的安全解决方案的有效性和效率。

https://cdn.ncbi.nlm.nih.gov/pmc/blobs/3826/6679272/fbeec82be22d/sensors-19-03119-g001.jpg

文献AI研究员

20分钟写一篇综述,助力文献阅读效率提升50倍。

立即体验

用中文搜PubMed

大模型驱动的PubMed中文搜索引擎

马上搜索

文档翻译

学术文献翻译模型,支持多种主流文档格式。

立即体验