Risk based Security Enforcement in Software Defined Network

被引:6
|
作者
Tripathy, Bata Krishna [1 ]
Das, Debi Prasad [2 ]
Jena, Swagat Kumar [1 ]
Bera, Padmalochan [1 ]
机构
[1] Indian Inst Technol Bhubaneswar, Sch Elect Sci, Bhubaneswar, India
[2] Natl Inst Technol Rourkela, Dept Comp Sci & Engn, Rourkela, India
关键词
Software Defined Network (SDN); Network control functions (NF); Common Vulnerability Scoring System (CVSS); Vulnerability; Exposure; Threat; Risk;
D O I
10.1016/j.cose.2018.07.010
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Software Defined Network (SDN) paradigm provides intelligent and efficient management of different network control functions (NF) depending on changes in traffic behavior, service providers' requirements and application context. However, the logical centralization of controllers' functions opens up challenges towards enforcing security perimeter over the underlying network and the assets involved. In this paper, we propose a risk assessment model for pro-active secure flow control and routing of traffic in SDN. The proposed model determines threat value of different SDN entities by analyzing vulnerability and exposure with respect to Common Vulnerability Scoring System (CVSS). The risk of a given traffic is calculated as cumulative threat values of the SDN entities that guides the flow and routing control functions in generating secure flow rules for the forwarding switches. The efficacy of the proposed model is demonstrated through extensive case studies of an enterprise network. (C) 2018 Elsevier Ltd. All rights reserved.
引用
收藏
页码:321 / 335
页数:15
相关论文
共 50 条
  • [1] Cloud Security Solution Based on Software Defined Network
    Zhao, Shengli
    Li, Zhaochan
    Cao, Ning
    [J]. CYBERSPACE SAFETY AND SECURITY, PT I, 2020, 11982 : 562 - 574
  • [2] An Experimental Software Defined Security Controller for Software Defined Network
    Al-Zewairi, Malek
    Suleiman, Dima
    Almajali, Sufyan
    [J]. 2017 FOURTH INTERNATIONAL CONFERENCE ON SOFTWARE DEFINED SYSTEMS (SDS), 2017, : 32 - 36
  • [3] A Software Defined Network information security risk assessment based on Pythagorean fuzzy sets
    Deb, Raktim
    Roy, Sudipta
    [J]. EXPERT SYSTEMS WITH APPLICATIONS, 2021, 183
  • [4] A ZigBee Software Defined Network Security
    Basabi, Alireza Ebrahimi
    He, Jingsha
    Hashemi, Seyed Mahmood
    Xuan, Xinggang
    Pathan, Muhammad Salman
    Zardari, Zulfiqar Ali
    [J]. International Journal of Network Security, 2022, 24 (01) : 11 - 19
  • [5] Leveraging software-defined networking for security policy enforcement
    Liu, Jiaqiang
    Li, Yong
    Wang, Huandong
    Jin, Depeng
    Su, Li
    Zeng, Lieguang
    Vasilakos, Thanos
    [J]. INFORMATION SCIENCES, 2016, 327 : 288 - 299
  • [6] A novel Security Mechanism for Software Defined Network Based on Blockchain
    Guo, Xian
    Wang, Chen
    Cao, Laicheng
    Jiang, Yongbo
    Yan, Yan
    [J]. COMPUTER SCIENCE AND INFORMATION SYSTEMS, 2022, 19 (02) : 523 - 545
  • [7] A Software-Defined Security Strategy for Supporting Autonomic Security Enforcement in Distributed Cloud
    Compastie, Maxime
    Badonnel, Remi
    Festor, Olivier
    He, Ruan
    Kassi-Lahlou, Mohamed
    [J]. 2016 8TH IEEE INTERNATIONAL CONFERENCE ON CLOUD COMPUTING TECHNOLOGY AND SCIENCE (CLOUDCOM 2016), 2016, : 464 - 467
  • [8] Security Challenges in Software Defined Network and their Solutions
    Patil, Varsha
    Patil, Charulata
    Awale, R. N.
    [J]. 2017 8TH INTERNATIONAL CONFERENCE ON COMPUTING, COMMUNICATION AND NETWORKING TECHNOLOGIES (ICCCNT), 2017,
  • [9] Exploring the Security of Software Defined Network Controllers
    Kaur, Prabhjot
    Patel, Shiv
    Mittal, Sanjana
    Sharma, Surbhi
    Butakov, Sergey
    [J]. INFORMATICS AND INTELLIGENT APPLICATIONS, 2022, 1547 : 165 - 178
  • [10] Privacy preservation and security management in VANET based to Software Defined Network
    Assafra, Khadija
    Alaya, Bechir
    Abid, Mohamed
    [J]. 2022 IEEE WIRELESS COMMUNICATIONS AND NETWORKING CONFERENCE (WCNC), 2022, : 96 - 101