Citadel: Cyber threat intelligence assisted defense system for software-defined networks

被引:7
作者
Yurekten, Ozgur [1 ,2 ]
Demirci, Mehmet [1 ]
机构
[1] Gazi Univ, Dept Comp Engn, Ankara, Turkey
[2] TUBITAK BILGEM, Cyber Secur Inst, Ankara, Turkey
关键词
Cyber security; Cyber defense; Cyber threat intelligence; CTI; Software-defined networking; SDN; Network function virtualization; NFV; Service function chaining; SFC; SECURITY;
D O I
10.1016/j.comnet.2021.108013
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Defending networks is becoming more challenging due to the growing number and variety of cyber threats. On the other hand, network security professionals have new technologies and tools at their disposal. This paper focuses on a few of these technologies and investigates new ways to take advantage of them. To this end, we present Citadel, a novel security system utilizing cyber threat intelligence (CTI) to construct automated defense solutions in software-defined networking (SDN) environments. Citadel also incorporates network function virtualization (NFV) and service function chaining (SFC) to achieve flexible, cost-efficient, and proactive network defense. We examine CTI data to extract common attacker models and design security services as virtual network functions chained together using SFC to counter these threats. The modular and extensible nature of Citadel makes it suitable for incremental deployment in networks. Besides, we propose a new CTI data model to use as an extension of the existing CTI models for better compatibility with automated network defense. Extensive evaluations demonstrate that our proposals are applicable and effectively facilitate the management of agile defense in SDN/NFV-enabled networks.
引用
收藏
页数:25
相关论文
共 65 条
[41]   A Defense Mechanism of Random Routing Mutation in SDN [J].
Liu, Jiang ;
Zhang, Hongqi ;
Guo, Zhencheng .
IEICE TRANSACTIONS ON INFORMATION AND SYSTEMS, 2017, E100D (05) :1046-1054
[42]   OpenFlow: Enabling innovation in campus networks [J].
McKeown, Nick ;
Anderson, Tom ;
Balakrishnan, Hari ;
Parulkar, Guru ;
Peterson, Larry ;
Rexford, Jennifer ;
Shenker, Scott ;
Turner, Jonathan .
ACM SIGCOMM COMPUTER COMMUNICATION REVIEW, 2008, 38 (02) :69-74
[43]   NIMBUS: Cloud-scale Attack Detection and Mitigation [J].
Miao, Rui ;
Yu, Minlan ;
Jain, Navendu .
ACM SIGCOMM COMPUTER COMMUNICATION REVIEW, 2014, 44 (04) :121-122
[44]   Semantic-Aware Security Orchestration in SDN/NFV-Enabled IoT Systems [J].
Molina Zarca, Alejandro ;
Bagaa, Miloud ;
Bernal Bernabe, Jorge ;
Taleb, Tarik ;
Skarmeta, Antonio F. .
SENSORS, 2020, 20 (13) :1-26
[45]   Security Management Architecture for NFV/SDN-Aware IoT Systems [J].
Molina Zarca, Alejandro ;
Bernal Bernabe, Jorge ;
Trapero, Ruben ;
Rivera, Diego ;
Villalobos, Jesus ;
Skarmeta, Antonio ;
Bianchi, Stefano ;
Zafeiropoulos, Anastasios ;
Gouvas, Panagiotis .
IEEE INTERNET OF THINGS JOURNAL, 2019, 6 (05) :8005-8020
[46]   Data-driven analytics for cyber-threat intelligence and information sharing [J].
Qamar, Sara ;
Anwar, Zahid ;
Rahman, Mohammad Ashiqur ;
Al-Shaer, Ehab ;
Chu, Bei-Tseng .
COMPUTERS & SECURITY, 2017, 67 :35-58
[47]   Software Defined Networking Architecture, Security and Energy Efficiency: A Survey [J].
Rawat, Danda B. ;
Reddy, Swetha R. .
IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2017, 19 (01) :325-346
[48]  
Reich Joshua., 2013, Modular SDN Programming with Pyretic
[49]   CINDAM: Customized Information Networks for Deception and Attack Mitigation [J].
Robertson, Seth ;
Alexander, Scott ;
Micallef, Josephine ;
Pucci, Jonathan ;
Tanis, James ;
Macera, Anthony .
2015 IEEE NINTH INTERNATIONAL CONFERENCE ON SELF-ADAPTIVE AND SELF-ORGANIZING SYSTEMS WORKSHOPS (SASOW), 2015, :114-119
[50]  
Rodrigues Bruno, 2017, Security of Networks and Services in an All-Connected World. 11th IFIP WG 6.6 International Conference on Autonomous Infrastructure, Management and Security, AIMS 2017. Proceedings: LNCS 10356, P16, DOI 10.1007/978-3-319-60774-0_2