首页> 外文会议>International Scientific and Technical Conference Modern Computer Network Technologies >“Common Criteria” and Software-Defined Network (SDN) Security
【24h】

“Common Criteria” and Software-Defined Network (SDN) Security

机译:“通用标准”和软件定义网络(SDN)安全性

获取原文

摘要

“Common criteria” (ISO 15408) is a universally recognized and broadly applicable approach to information security solutions management and evaluation. “Common criteria” leans on developing a shared conceptual basis for key security solution modules including protection profiles and security targets. Conceptual basis development implies defining the following elements: security objectives and assumptions (for the environment and the object), threats and security policies, as well as functional and assurance requirements. The specifics of SDN security solutions is largely driven by fundamental architectural principles of SDN technology itself-primarily by the separation of control and data flows, - and by conditions imposed by Open Flow protocol application. However, proactive (threats and policies), passive (objectives and assumptions) and reactive (requirements) aspects of security management remain highly relevant for this type of security solutions. This paper discusses the Common Criteria application specifics for assessing the of SDN security and practical MTUCI experience in the development of the protection profile. A new class of network attacks on SDN switches and controllers can involve either data or control components. In addition to traditional vulnerabilities, centralization of management functions paves way for new security threats by isolating controller's activity and administrative message exchange. Therefore, identifying and analyzing threats, policies and requirements specific to SDN control module security becomes an emergina priority.
机译:“通用标准”(ISO 15408)是信息安全解决方案管理和评估的一种公认且广泛适用的方法。 “通用标准”取决于为关键安全解决方案模块(包括保护配置文件和安全目标)开发共享的概念基础。概念基础开发意味着定义以下元素:安全目标和假设(针对环境和对象),威胁和安全策略以及功能和保证要求。 SDN安全解决方案的具体细节在很大程度上取决于SDN技术本身的基本体系结构原理,主要是控制和数据流的分离以及Open Flow协议应用程序施加的条件。但是,安全管理的主动(威胁和策略),被动(目标和假设)和被动(需求)方面仍然与此类安全解决方案高度相关。本文讨论了用于评估SDN安全性和保护配置文件开发中的实际MTUCI经验的通用标准应用程序细节。对SDN交换机和控制器的新型网络攻击可能涉及数据或控制组件。除传统漏洞外,管理功能的集中化通过隔离控制器的活动和管理消息交换,为新的安全威胁铺平了道路。因此,识别和分析特定于SDN控制模块安全性的威胁,策略和要求已成为当务之急。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号