首页> 外文学位 >Zero-Day Vulnerability In Software-Defined Networks: A Quantitative Study
【24h】

Zero-Day Vulnerability In Software-Defined Networks: A Quantitative Study

机译:软件定义网络中的零日漏洞:定量研究

获取原文
获取原文并翻译 | 示例

摘要

The increased adoption of Software defined-network (SDN) technology in the telecommunications infrastructure presents a potential for cyber-attack due to the existence of zero-day vulnerability. Due to their unknown characteristics, the zero-day vulnerability is practically challenging to detect or eradicate using traditional antivirus, firewall, or other intrusion detection system. This weakness has become a recurring challenge to the computer scientist, system administrators, functional leaders, organizations, and nation states. The centralized design model for SDN makes the controller the most viable component that facilitates the abstraction of network traffic from user data applications. This quantitative study investigated the 15 zero-day vulnerabilities found during a race condition attack on three SDN controllers. The secondary data were analyzed with the IBM SPSS software to determine the correlation that exists between the three SDN controller and the characteristics of the zero-day vulnerability. The findings of the study provided meaningful answers to the three research questions and hypothesis. The game theory framework provided insight into the empirical evidence obtained between the variables. The results obtained from the study facilitate understanding value-at-risk assessment among telecoms service provider, executive managers, and information security practitioners. The research shows there is a strong correlation between SDN controller and the zero-day vulnerability. The study also indicates that remote access and admin privileges were the primary sources of exploiting the zero-day vulnerability. Further findings mean the disruption of one controller has a damaging effect on SDN network services thereby impacting the quality of services.
机译:由于存在零日漏洞,因此在电信基础架构中对软件定义网络(SDN)技术的越来越多的采用提出了网络攻击的潜力。由于其零日特征,使用传统的防病毒,防火墙或其他入侵检测系统检测或消除零日漏洞实际上具有挑战性。对于计算机科学家,系统管理员,职能领导者,组织和民族国家,这种弱点已成为一个反复出现的挑战。 SDN的集中式设计模型使控制器成为最可行的组件,可促进从用户数据应用程序抽象网络流量。这项定量研究调查了在对三个SDN控制器进行的竞赛条件攻击期间发现的15个零日漏洞。使用IBM SPSS软件分析了辅助数据,以确定三个SDN控制器与零日漏洞的特征之间存在的关联。研究结果为三个研究问题和假设提供了有意义的答案。博弈论框架提供了对变量之间获得的经验证据的见识。从研究中获得的结果有助于理解电信服务提供商,执行经理和信息安全从业人员的风险价值评估。研究表明,SDN控制器与零日漏洞之间有很强的相关性。该研究还表明,远程访问和管理员特权是利用零日漏洞的主要来源。进一步的发现意味着,一个控制器的中断会对SDN网络服务产生破坏性影响,从而影响服务质量。

著录项

  • 作者单位

    Colorado Technical University.;

  • 授予单位 Colorado Technical University.;
  • 学科 Computer science.;Information technology.;Electrical engineering.
  • 学位 D.C.S.
  • 年度 2018
  • 页码 142 p.
  • 总页数 142
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

  • 入库时间 2022-08-17 11:52:58

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号