首页> 外文会议>International Arab Conference on Information Technology >Zero-Day Attack Detection and Prevention in Software-Defined Networks
【24h】

Zero-Day Attack Detection and Prevention in Software-Defined Networks

机译:软件定义网络中的零日攻击检测和预防

获取原文

摘要

The zero-day attack in networks exploits an undiscovered vulnerability, in order to affect/damage networks or programs. The term “zero-day” refers to the number of days available to the software or the hardware vendor to issue a patch for this new vulnerability. Currently, the best-known defense mechanism against the zero-day attacks focuses on detection and response, as a prevention effort, which typically fails against unknown or new vulnerabilities. To the best of our knowledge, this attack has not been widely investigated for Software-Defined Networks (SDNs). Therefore, in this work we are motivated to develop anew zero-day attack detection and prevention mechanism, which is designed and implemented for SDN using a modified sandbox tool, named Cuckoo. Our experiments results, under UNIX system, show that our proposed design successfully stops zero-day malwares by isolating the infected client, and thus, prevents these malwares from infesting other clients.
机译:网络中的零日攻击利用未发现的漏洞来影响/损坏网络或程序。术语“零日”是指软件或硬件供应商可用于为该新漏洞发布补丁程序的天数。当前,最著名的针对零时差攻击的防御机制侧重于检测和响应,作为一种预防措施,通常无法防范未知或新的漏洞。据我们所知,这种攻击尚未针对软件定义网络(SDN)进行广泛调查。因此,在这项工作中,我们有动力开发一种新的零日攻击检测和防御机制,该机制是使用名为Cuckoo的改进的沙盒工具为SDN设计和实现的。在UNIX系统下,我们的实验结果表明,我们提出的设计通过隔离受感染的客户端成功停止了零日恶意软件,从而防止了这些恶意软件感染其他客户端。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号