Generalized Stochastic Petri Net Model Based Security Risk Assessment of Software Defined Networks

被引:0
|
作者
Almutairi, Laila M. [1 ]
Shetty, Sachin [2 ]
机构
[1] Tennessee State Univ, Dept Elect & Comp Engn, Nashville, TN 37203 USA
[2] Old Dominion Univ, Virginia Modeling Anal & Simulat Ctr, Norfolk, VA USA
关键词
Software-defined networking (SDN); Security Attack tree; Petri Net (PN); Generalized Stochastic Petri Net (GSPN); link layer discovery protocol (LLDP); Datapath ID (DPID); Denial of Service (DoS);
D O I
暂无
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
Software-defined networking (SDN) is a networking paradigm to provide automated network management at run time through network orchestration and virtualization. A central controller realizes the automatic network configuration in SDN at run time by conforming to a control plane protocol (e.g., OpenFlow) and switches act as simple forwarding devices. However, SDN are susceptible to cyber attacks and there is a need to understand and quantify the cyber risks. In this paper, we present a model to analyze attacks on SDN and generate risk assessment scores that can aid mitigation. We build and analyze a Generalized Stochastic Petri Net (GSPN) model for Denial of Service attack in SDN using the PIPE tool. The results show all possible attacker paths during the attack. Moreover, they indicate that there is a direct relation between the risk score of the transitions and the average time the attacker needs to successfully perform individual attack action. These results can be used to improve countermeasures of SDN attacks in future work.
引用
下载
收藏
页码:545 / 550
页数:6
相关论文
共 50 条
  • [31] A Survey of Security in Software Defined Networks
    Scott-Hayward, Sandra
    Natarajan, Sriram
    Sezer, Sakir
    IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2016, 18 (01): : 623 - 654
  • [32] Security in Software Defined Networks: A Survey
    Ahmad, Ijaz
    Namal, Suneth
    Ylianttila, Mika
    Gurtov, Andrei
    IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2015, 17 (04): : 2317 - 2346
  • [33] Security of Software Defined Networks: A survey
    Alsmadr, Izzat
    Xu, Dianxiang
    COMPUTERS & SECURITY, 2015, 53 : 79 - 108
  • [34] The (In)Security of Virtualization in Software Defined Networks
    Alharbi, Talal
    Portmann, Marius
    IEEE ACCESS, 2019, 7 : 66584 - 66594
  • [35] An improved network security situation assessment approach in software defined networks
    Zhijie Fan
    Ya Xiao
    Amiya Nayak
    Chengxiang Tan
    Peer-to-Peer Networking and Applications, 2019, 12 : 295 - 309
  • [36] An improved network security situation assessment approach in software defined networks
    Fan, Zhijie
    Xiao, Ya
    Nayak, Amiya
    Tan, Chengxiang
    PEER-TO-PEER NETWORKING AND APPLICATIONS, 2019, 12 (02) : 295 - 309
  • [37] S2Net: A Security Framework for Software Defined Intelligent Building Networks
    Xue, Nian
    Huang, Xin
    Zhang, Jie
    2016 IEEE TRUSTCOM/BIGDATASE/ISPA, 2016, : 654 - 661
  • [38] Quantitative Software Security Risk Assessment Model
    Mkpong-Ruffin, Idongesit
    Umphress, David
    Hamilton, John
    Gilbert, Juan
    QOP'07: PROCEEDINGS OF THE 2007 ACM WORKSHOP ON QUALITY OF PROTECTION, 2007, : 31 - 33
  • [39] The risk assessment model of TOT concession period based on Time Fuzzy Petri Net
    Shen, Jun-xin
    Wang, Song-jiang
    PROCEEDINGS OF THE 1ST INTERNATIONAL CONFERENCE ON SUSTAINABLE CONSTRUCTION & RISK MANAGEMENT, VOLS I AND II, 2010, : 1328 - 1333
  • [40] CPS Information Security Risk Evaluation System Based on Petri Net
    Fu, Yonggui
    Zhu, Jianming
    Gao, Sheng
    2017 IEEE SECOND INTERNATIONAL CONFERENCE ON DATA SCIENCE IN CYBERSPACE (DSC), 2017, : 541 - 548