Smart contract based DDoS attack traceability audit mechanism in intelligent IoT
【Author】 Wang, Zhuohao; Zhang, Weiting; Wang, Runhu; Liu, Ying; Xu, Chenyang; Yu, Chengxiao
【Source】CHINA COMMUNICATIONS
【影响因子】3.170
【Abstract】In this paper, we focus on providing data provenance auditing schemes for distributed denial of service (DDoS) defense in intelligent internet of things (IoT). To achieve effective DDoS defense, we introduce a two-layer collaborative blockchain framework to support data auditing. Specifically, using data scattered among intelligent IoT devices, switch gateways self-assemble a layer of blockchain in the local autonomous system (AS), and the main chain with controller participation can be aggregated by its associated layer of blocks once a cycle, to obtain a global security model. To optimize the processing delay of the security model, we propose a process of data pre-validation with the goal of ensuring data consistency while satisfying overhead requirements. Since the flood of identity spoofing packets, it is difficult to solve the identity consistency of data with traditional detection methods, and accountability cannot be pursued afterwards. Thus, we proposed a Packet Traceback Telemetry (PTT) scheme, based on in-band telemetry, to solve the problem. Specifically, the PTT scheme is executed on the distributed switch side, the controller to schedule and select routing policies. Moreover, a tracing probabilistic optimization is embedded into the PTT scheme to accelerate path reconstruction and save device resources. Simulation results show that the PTT scheme can reconstruct address spoofing packet forward path, reduce the resource consumption compared with existing tracing scheme. Data tracing audit method has fine-grained detection and feasible performance.
【Keywords】smart contract; Internet of Things; distributed denial of service; telemetry; audit
【发表时间】2023 AUG
【收录时间】2023-09-23
【文献类型】实验仿真
【主题类别】
区块链技术-协同技术-物联网
评论