Towards adding digital forensics capabilities in software defined networking based moving target defense

被引:0
|
作者
Muhammad Faraz Hyder
Tasbiha Fatima
Saadia Arshad
机构
[1] NED University of Engineering and Technology,Department of Software Engineering
[2] NED University of Engineering and Technology,Department of Computer Science & Information Technology
来源
Cluster Computing | 2024年 / 27卷
关键词
Moving target defense; Software defined networking; SDN Forensics; MTD-based SDN forensics; Distributed denial of service attacks;
D O I
暂无
中图分类号
学科分类号
摘要
Moving Target Defense (MTD) is a security technique for Software Defined Networks (SDN) to change the attack surface constantly. Although MTD is an effective technique, it makes the digital forensics procedure challenging due to high transitions in the system state. There is an ever-increasing requirement for SDN forensics due to the increasing number of cyberattacks and the adoption of SDN by large-scale cloud service providers, telecommunication operators, and internet service providers. In this paper, we have proposed a digital forensics scheme for MTD-based SDN to record every movement of the MTD for collecting attack-related evidence, especially the attacker (attack source), to augment the forensics investigation. The proposed technique consists of a three-level logging mechanism. The first one is the native logging technique of ONOS. The second is a Java-based logging application called “Java ONOS Logs Collector (JOLC)”, developed to capture MTD-based SDN logs. Lastly, we utilized the Fluentd unified logging tool to dig out evidential data from MTD logs. The experimental testbed comprises an ONOS SDN controller, Mininet, and an event-based MTD application running over SDN using JSON FlowRule scripts on the ONOS controller while using sflow-rt to detect the level of attack/number of packets sent by the attacker. The native ONOS logging mechanism provides initial-level artifacts. The developed JOLC application creates separate files for ONOS and Mininet/host machine logs stored with the current timestamp. Fluentd generates a single file for the SDN controller, Mininet, and host machine logs, along with the flow rule entry into the SDN controller. Experimental results confirmed that our proposed multi-level forensics technique successfully collected all the relevant records.
引用
收藏
页码:893 / 912
页数:19
相关论文
共 50 条
  • [1] Towards adding digital forensics capabilities in software defined networking based moving target defense
    Hyder, Muhammad Faraz
    Fatima, Tasbiha
    Arshad, Saadia
    CLUSTER COMPUTING-THE JOURNAL OF NETWORKS SOFTWARE TOOLS AND APPLICATIONS, 2024, 27 (01): : 893 - 912
  • [2] Towards Dynamically Shifting Cyber Terrain With Software-Defined Networking and Moving Target Defense
    Larkin, Robert
    Jensen, Steven
    Koranek, Daniel
    Mullins, Barry
    Reith, Mark
    PROCEEDINGS OF THE 16TH INTERNATIONAL CONFERENCE ON CYBER WARFARE AND SECURITY (ICCWS 2021), 2021, : 535 - 540
  • [3] Moving Target Defense Against Network Reconnaissance with Software Defined Networking
    Wang, Li
    Wu, Dinghao
    INFORMATION SECURITY, (ISC 2016), 2016, 9866 : 203 - 217
  • [4] Towards Enhancing the Endpoint Security using Moving Target Defense (Shuffle-based Approach) in Software Defined Networking
    Hyder, Muhammad Faraz
    Waseemullah
    Farooq, Muhammad Umer
    Ahmed, Usama
    Raza, Wajahat
    ENGINEERING TECHNOLOGY & APPLIED SCIENCE RESEARCH, 2021, 11 (04) : 7483 - 7488
  • [5] Performance and Security Evaluation of a Moving Target Defense Based on a Software-Defined Networking Environment
    Kim, Minjune
    Cho, Jin-Hee
    Lim, Hyuk
    Moore, Terrence J.
    Nelson, Frederica F.
    Kim, Dan Dongseong
    2022 IEEE 27TH PACIFIC RIM INTERNATIONAL SYMPOSIUM ON DEPENDABLE COMPUTING (PRDC), 2022, : 119 - 129
  • [6] Look Again, Neo: A Software-Defined Networking Moving Target Defense
    Mayer, Samuel
    Reith, Mark
    Mullins, Barry
    PROCEEDINGS OF THE 13TH INTERNATIONAL CONFERENCE ON CYBER WARFARE AND SECURITY (ICCWS 2018), 2018, : 602 - 610
  • [7] Design and Performance Analysis of Software Defined Networking based Web Services Adopting Moving Target Defense
    Kim, Dong Seong
    Kim, Minjune
    Cho, Jin-Hee
    Lim, Hyuk
    Moore, Terrence J.
    Nelson, Frederica F.
    2020 50TH ANNUAL IEEE-IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS-SUPPLEMENTAL VOLUME (DSN-S), 2020, : 43 - 44
  • [8] Frequency-Minimal Moving Target Defense using Software-Defined Networking
    Debroy, Saptarshi
    Calyam, Prasad
    Nguyen, Minh
    Stage, Allen
    Georgiev, Vladimir
    2016 INTERNATIONAL CONFERENCE ON COMPUTING, NETWORKING AND COMMUNICATIONS (ICNC), 2016,
  • [9] Securing Software-Defined Networks Through Adaptive Moving Target Defense Capabilities
    Felipe S. Dantas Silva
    Emidio P. Neto
    Rodrigo S. S. Nunes
    Cristian H. M. Souza
    Augusto J. V. Neto
    Túlio Pascoal
    Journal of Network and Systems Management, 2023, 31
  • [10] Securing Software-Defined Networks Through Adaptive Moving Target Defense Capabilities
    Silva, Felipe Dantas S.
    Neto, Emidio P.
    Nunes, Rodrigo S. S.
    Souza, Cristian H. M.
    Neto, Augusto J. V.
    Pascoal, Tulio
    JOURNAL OF NETWORK AND SYSTEMS MANAGEMENT, 2023, 31 (03)