信息网络安全 ›› 2022, Vol. 22 ›› Issue (11): 36-46.doi: 10.3969/j.issn.1671-1122.2022.11.005

• 技术研究 • 上一篇    下一篇

SD-IoT中基于设备地址的移动目标防御机制研究

韩俐1, 宋吉祥1, 孙士民2()   

  1. 1. 天津理工大学计算机科学与工程学院,天津 300384
    2. 天津工业大学软件学院,天津 300387
  • 收稿日期:2022-07-12 出版日期:2022-11-10 发布日期:2022-11-16
  • 通讯作者: 孙士民 E-mail:sunshimin@tiangong.edu.cn
  • 作者简介:韩俐(1983—),女,内蒙古,副教授,博士,主要研究方向为软件定义安全、软件定义网络、网络空间安全|宋吉祥(1996—),男,河南,硕士研究生,主要研究方向为网络信息安全、移动目标防御|孙士民(1983—),男,山东,副教授,博士,主要研究方向为软件定义网络、网络空间安全、QoS优化算法
  • 基金资助:
    国家自然科学基金(61802281);国家自然科学基金(61702366);国家自然科学基金(61972456);天津市自然科学基金(19JCYBJC15800);专用集成电路与系统国家重点实验室(复旦大学)

Moving Target Defense Mechanism Research Based on Device Address in SD-IoT

HAN Li1, SONG Jixiang1, SUN Shimin2()   

  1. 1. School of Computer Science and Engineering, Tianjin University of Technology, Tianjin 300384, China
    2. School of Software, Tiangong University, Tianjin 300387, China
  • Received:2022-07-12 Online:2022-11-10 Published:2022-11-16
  • Contact: SUN Shimin E-mail:sunshimin@tiangong.edu.cn

摘要:

物联网终端设备资源受限与静态配置的特性会导致嗅探攻击对设备地址(IP地址或MAC地址)的窃取或篡改,地址跳变策略通过动态随机化网络设备的地址来抵御攻击者的入侵。文章在软件定义物联网环境下提出一种加权随机选择的设备地址跳变方法,通过对跳变过程中虚拟地址的选择添加重复约束条件,以增强设备地址跳变过程中的不可预测性,抵御嗅探行为的发生;同时,利用SDN控制器集中控制的特性,对物联网终端设备进行检测,以确保地址跳变策略的正常部署;并根据检测结果动态调整地址跳变周期,以提高网络的服务能力与安全性。仿真实验表明,在系统负载5%范围内,该方法能够增强设备地址的不可预测性,并抵御物联网中嗅探与欺骗行为的发生。

关键词: 软件定义物联网, 加权随机选择, 嗅探, 跳变周期

Abstract:

The limited resources and static configuration of Internet of Things(IoT) terminal devices can lead to sniffing attack which causes theft and tampering of the device address (IP address or MAC address). The address hopping strategy defends against attackers by dynamically randomizing the address of the network device. In this paper, a weighted random selection of device address hopping method is proposed in the software defined Internet of things(SD-IoT) environment. By adding repeated constraints to the selection of virtual addresses in the hopping process, it can enhance the unpredictability of the device address hopping process and defend the occurrence of sniffing behavior. At the same time, the characteristics of centralized control of the SDN controller are used to detect the terminal equipment of the IoT to ensure the normal deployment of the address hopping strategy. According to the detection results, the address hopping period is dynamically adjusted to improve the performance of the service capability of network and security. Simulation results show that, within 5% of the system load, the proposed method can enhance the unpredictability of device addresses, and resist sniffing and spoofing behaviors in the IoT.

Key words: software defined Internet of things, weighted random select, sniffing, hopping period

中图分类号: