A moving target defense and network forensics framework for ISP networks using SDN and NFV

被引:38
|
作者
Aydeger, Abdullah [1 ]
Saputro, Nico [1 ]
Akkaya, Kemal [1 ]
机构
[1] Florida Int Univ, Dept Elect & Comp Engn, Miami, FL 33174 USA
关键词
Moving target defense; Network forensics; SDN; NFV; Crossfire attacks;
D O I
10.1016/j.future.2018.11.045
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
With the increasing diversity of network attacks, there is a trend towards building more agile networks that can defend themselves or prevent attackers to easily launch attacks. To this end, moving target defense (MTD) mechanisms have started to be pursued to dynamically change the structure and configuration of the networks not only during an attack but also before an attack so that conducting network reconnaissance will become much more difficult. Furthermore, various network forensics mechanisms are introduced to help locating the source and types of attacks as a reactive defense mechanism. Emerging Software Defined Networking (SDN) and Network Function Virtualization (NFV) provide excellent opportunities to implement these mechanisms efficiently. This paper considers MTD in the context of an Internet Service Provider (ISP) network and proposes an architectural framework that will enable it even at the reconnaissance phase while facilitating forensics investigations. We propose various virtual shadow networks through NFV to be used when implementing MTD mechanisms via route mutation. The idea is to dynamically change the routes for specific reconnaissance packets so that attackers will not be able to easily identify the actual network topologies for potential distributed denial of service attacks (DDoS) such as Crossfire while enabling the defender to store potential attacker's information through a forensics feature. We present an integrated framework that encompasses these features. The proposed framework is implemented in Mininet to test its effectiveness and overheads. The results demonstrated the effectiveness in terms of failing the attackers at the expense of slightly increased path lengths, end-to-end delay and storage for forensic purposes. (C) 2018 Elsevier B.V. All rights reserved.
引用
收藏
页码:496 / 509
页数:14
相关论文
共 50 条
  • [41] A Survey on Moving Target Defense for Networks: A Practical View
    Jalowski, Lukasz
    Zmuda, Marek
    Rawski, Mariusz
    [J]. ELECTRONICS, 2022, 11 (18)
  • [42] Analysis of Network Address Shuffling as a Moving Target Defense
    Carroll, Thomas E.
    Crouse, Michael
    Fulp, Errin W.
    Berenhaut, Kenneth S.
    [J]. 2014 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2014, : 701 - 706
  • [43] TOTP Moving Target Defense for sensitive network services
    Cunha, Vitor A.
    Corujo, Daniel
    Barraca, Joao P.
    Aguiar, Rui L.
    [J]. PERVASIVE AND MOBILE COMPUTING, 2021, 74
  • [44] Scalable Anti-Censorship Framework Using Moving Target Defense for Web Servers
    Heydari, Vahid
    Kim, Sun-il
    Yoo, Seong-Moo
    [J]. IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2017, 12 (05) : 1113 - 1124
  • [45] MERLINS - Moving Target Defense Enhanced with Deep-RL for NFV In-Depth Security
    Soussi, Wissem
    Christopoulou, Maria
    Guer, Gurkan
    Stiller, Burkhard
    [J]. 2023 IEEE CONFERENCE ON NETWORK FUNCTION VIRTUALIZATION AND SOFTWARE DEFINED NETWORKS, NFV-SDN, 2023, : 65 - 71
  • [46] IANVS: A Moving Target Defense Framework for a Resilient Internet of Things
    Navas, Renzo E.
    Sandaker, Hakon
    Cuppens, Frederic
    Cuppens, Nora
    Toutain, Laurent
    Papadopoulos, Georgios Z.
    [J]. 2020 IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATIONS (ISCC), 2020, : 518 - 523
  • [47] Using Dynamic Addressing for a Moving Target Defense
    Groat, Stephen
    Dunlop, Matthew
    Marchany, Randy
    Tront, Joseph
    [J]. PROCEEDINGS OF THE 6TH INTERNATIONAL CONFERENCE ON INFORMATION WARFARE AND SECURITY, 2011, : 84 - 91
  • [48] How to Defend against Sophisticated Intrusions in Home Networks Using SDN and NFV
    Luo, Shibo
    Wang, Hongkai
    Wu, Jun
    Li, Jianhua
    Guo, Longhua
    Pei, Bei
    [J]. 2016 IEEE 83RD VEHICULAR TECHNOLOGY CONFERENCE (VTC SPRING), 2016,
  • [49] A SDN-based Deployment Framework for Computer Network Defense Policy
    Gao, Jinghua
    Xia, Chunhe
    Wang, Shuguang
    Zhang, Huajun
    [J]. PROCEEDINGS OF 2015 4TH INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE AND NETWORK TECHNOLOGY (ICCSNT 2015), 2015, : 1253 - 1258
  • [50] Improving Energy Efficiency in Industrial Wireless Sensor Networks Using SDN and NFV
    Luo, Shibo
    Wang, Hongkai
    Wu, Jun
    Li, Jianhua
    Guo, Longhua
    Pei, Bei
    [J]. 2016 IEEE 83RD VEHICULAR TECHNOLOGY CONFERENCE (VTC SPRING), 2016,