首页> 外文期刊>Future generation computer systems >A moving target defense and network forensics framework for ISP networks using SDN and NFV
【24h】

A moving target defense and network forensics framework for ISP networks using SDN and NFV

机译:使用SDN和NFV的ISP网络的移动目标防御和网络取证框架

获取原文
获取原文并翻译 | 示例
       

摘要

With the increasing diversity of network attacks, there is a trend towards building more agile networks that can defend themselves or prevent attackers to easily launch attacks. To this end, moving target defense (MTD) mechanisms have started to be pursued to dynamically change the structure and configuration of the networks not only during an attack but also before an attack so that conducting network reconnaissance will become much more difficult. Furthermore, various network forensics mechanisms are introduced to help locating the source and types of attacks as a reactive defense mechanism. Emerging Software Defined Networking (SDN) and Network Function Virtualization (NFV) provide excellent opportunities to implement these mechanisms efficiently. This paper considers MTD in the context of an Internet Service Provider (ISP) network and proposes an architectural framework that will enable it even at the reconnaissance phase while facilitating forensics investigations. We propose various virtual shadow networks through NFV to be used when implementing MTD mechanisms via route mutation. The idea is to dynamically change the routes for specific reconnaissance packets so that attackers will not be able to easily identify the actual network topologies for potential distributed denial of service attacks (DDoS) such as Crossfire while enabling the defender to store potential attacker's information through a forensics feature. We present an integrated framework that encompasses these features. The proposed framework is implemented in Mininet to test its effectiveness and overheads. The results demonstrated the effectiveness in terms of failing the attackers at the expense of slightly increased path lengths, end-to-end delay and storage for forensic purposes. (C) 2018 Elsevier B.V. All rights reserved.
机译:随着网络攻击的多样性不断增加,趋势是构建更敏捷的网络以保护自己或阻止攻击者轻松发起攻击。为此,已经开始追求移动目标防御(MTD)机制,不仅在攻击期间而且在攻击之前动态地改变网络的结构和配置,从而进行网络侦察将变得更加困难。此外,引入了各种网络取证机制以帮助定位攻击的来源和类型,作为一种反应式防御机制。新兴的软件定义网络(SDN)和网络功能虚拟化(NFV)为有效实施这些机制提供了极好的机会。本文在Internet服务提供商(ISP)网络的上下文中考虑了MTD,并提出了一种架构框架,该框架即使在侦察阶段也可以启用它,同时方便了法医调查。当通过路由突变实现MTD机制时,我们提出了通过NFV使用的各种虚拟影子网络。想法是动态更改特定侦察数据包的路由,以使攻击者无法轻松识别出潜在的分布式拒绝服务攻击(DDoS)(例如Crossfire)的实际网络拓扑,同时使防御者可以通过以下方式存储潜在的攻击者信息:取证功能。我们提出了一个包含这些功能的集成框架。建议的框架在Mininet中实现,以测试其有效性和开销。结果证明,以略微增加路径长度,端到端延迟和用于法医目的存储为代价,可以使攻击者无法胜任。 (C)2018 Elsevier B.V.保留所有权利。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号