In order to solve the security threat caused by malicious nodes in the Internet of Things transmission link to the data flow and transmission process, a Software Defined Network (SDN) based detection and location method of malicious nodes in the Internet of Things is proposed. The software defined network architecture is applied to the transmission process of data flow between edge nodes. The incoming switch node adds a forwarding verification header to the incoming data packet according to the forwarding path. Each downstream switch node verifies and forwards the data packet based on the header to ensure the integrity of the data packet and the consistency of the forwarding path, and sends the abnormal data packet that fails to pass the verification to the controller. The controller locates the malicious exchange node in the link through the header information. Finally, the proposed method is simulated and evaluated, and the experimental results show that the scheme is effective.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Detection and Localization of Malicious Nodes in Internet of Things Based on SDN

  • Xiao Jingxu,
  • Chang Chaowen,
  • Yuan Lu,
  • Ma Yingying,
  • Yang Chenli

摘要

In order to solve the security threat caused by malicious nodes in the Internet of Things transmission link to the data flow and transmission process, a Software Defined Network (SDN) based detection and location method of malicious nodes in the Internet of Things is proposed. The software defined network architecture is applied to the transmission process of data flow between edge nodes. The incoming switch node adds a forwarding verification header to the incoming data packet according to the forwarding path. Each downstream switch node verifies and forwards the data packet based on the header to ensure the integrity of the data packet and the consistency of the forwarding path, and sends the abnormal data packet that fails to pass the verification to the controller. The controller locates the malicious exchange node in the link through the header information. Finally, the proposed method is simulated and evaluated, and the experimental results show that the scheme is effective.