Toward a Robust WAN-Scale IoT-Fog Networks: A Distributed SDN Security Architecture Encompassing Monitoring, Scalability, Reliability, and Security
摘要
The proliferation of Internet of Things (IoT) devices and their connectivity has led to an increase in IoT traffic within cloud environments, making them vulnerable to cyber threats. Fog computing has emerged as a solution to address the limitations of cloud computing by providing low-latency services to IoT applications. However, fog devices deployed in proximity to IoT devices often lack sufficient security measures. The integration of Software-Defined Networks (SDN) and Network Function Virtualization (NFV) presents an opportunity for effective network management, coordination, and protection against network threats in IoT-Fog architectures. Establishing a secure framework requires a comprehensive network perspective and monitoring. This paper proposes a distributed SDN security infrastructure specifically designed for Wide Area Networks (WANs), enabling communication between IoT-Fog domains using traditional network infrastructures. The architecture provides comprehensive management and monitoring of all SDN-based IoT-Fog domains in WANs, utilizing the ONOS controller’s cluster-based architecture to ensure scalability and reliability. Furthermore, distributed Intrusion Detection System (IDS) nodes are deployed within these domains to enable real-time detection and mitigation of security threats. The proposed framework operates outside the network traffic band and does not impact the network latency for services. In this paper, we meticulously implement our proposed architecture utilizing the ONOS controller and evaluate its performance through various experiments. Our results demonstrate that the proposed architecture provides a robust and comprehensive solution compared to prior works in terms of security, intrusion detection and prevention, efficient monitoring and management, compatibility with traditional networks, as well as reliability and scalability.