TY - JOUR
T1 - Deep Learning for Securing Software-Defined Industrial Internet of Things
T2 - Attacks and Countermeasures
AU - Wang, Jiadai
AU - Liu, Jiajia
N1 - Publisher Copyright:
© 2014 IEEE.
PY - 2022/7/1
Y1 - 2022/7/1
N2 - Software-defined networking (SDN) has become an attractive solution to carry out centralized and efficient control in Industrial Internet of Things (IIoT). However, its security has received little attention when applied to IIoT, and no comprehensive consideration has been given to attacks against forwarding nodes (FNs), the basic elements of the data plane. Therefore, in this article, we aim to investigate attacks against FNs from multiple perspectives in software-defined IIoT. To the best of our knowledge, we are the first to systematically consider this kind of attacks. Since it is difficult to predeploy all defense methods against various attacks, we propose a deep reinforcement learning (DRL)-based general attack tolerance scheme to guide the benign traffic flow bypass the attacked FNs. Furthermore, in view of the situation that the real data set is rare and the standard model-based data set is likely to be impractical, we use generative adversarial network (GAN), a representative deep generative model (DGM), to flexibly generate real-like network traffic for more sufficient and effective experimental verification on the attack tolerance scheme. Experimental results show that our proposed scheme can significantly improve the successful arrival rate of IIoT traffic and achieve near-optimal results.
AB - Software-defined networking (SDN) has become an attractive solution to carry out centralized and efficient control in Industrial Internet of Things (IIoT). However, its security has received little attention when applied to IIoT, and no comprehensive consideration has been given to attacks against forwarding nodes (FNs), the basic elements of the data plane. Therefore, in this article, we aim to investigate attacks against FNs from multiple perspectives in software-defined IIoT. To the best of our knowledge, we are the first to systematically consider this kind of attacks. Since it is difficult to predeploy all defense methods against various attacks, we propose a deep reinforcement learning (DRL)-based general attack tolerance scheme to guide the benign traffic flow bypass the attacked FNs. Furthermore, in view of the situation that the real data set is rare and the standard model-based data set is likely to be impractical, we use generative adversarial network (GAN), a representative deep generative model (DGM), to flexibly generate real-like network traffic for more sufficient and effective experimental verification on the attack tolerance scheme. Experimental results show that our proposed scheme can significantly improve the successful arrival rate of IIoT traffic and achieve near-optimal results.
KW - Deep reinforcement learning (DRL)
KW - generative adversarial network (GAN)
KW - Industrial Internet of Things (IIoT)
KW - network security
KW - software-defined networking (SDN)
UR - http://www.scopus.com/inward/record.url?scp=85133282836&partnerID=8YFLogxK
U2 - 10.1109/JIOT.2021.3126633
DO - 10.1109/JIOT.2021.3126633
M3 - 文章
AN - SCOPUS:85133282836
SN - 2327-4662
VL - 9
SP - 11179
EP - 11189
JO - IEEE Internet of Things Journal
JF - IEEE Internet of Things Journal
IS - 13
ER -