S3: A DFW-based Scalable Security State Analysis Framework for Large-Scale Data Center Networks

01/14/2020
by   Abdulhakim Sabur, et al.
0

With an average network size approaching 8000 servers, datacenter networks need scalable security-state monitoring solutions. Using Attack Graph (AG) to identify possible attack paths and network risks is a common approach. However, existing AG generation approaches suffer from the state-space explosion issue. The size of AG increases exponentially as the number of services and vulnerabilities increases. To address this issue, we propose a network segmentation-based scalable security state management framework, called S3, which applies a divide-and-conquer approach to create multiple small-scale AGs (i.e., sub-AGs) by partitioning a large network into manageable smaller segments, and then merge them to establish the entire AG for the whole system. S3 utilizes SDN-based distributed firewall (DFW) for managing service reachability among different network segments. Therefore, it avoids reconstructing the entire system-level AG due to the dependencies among vulnerabilities. Our experimental analysis shows that S3 (i) reduces AG generation and analysis complexity by reducing AG’s density compared to existing AG-based solutions; (ii) utilizes SDN-based DFW to provide a granular security management framework, by incorporating security policies at the level of individual hosts and segments. In effect, S3 helps in limiting targeted slow and low attacks involving lateral movement.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
11/01/2018

SDFW: SDN-based Stateful Distributed Firewall

SDN provides a programmable command and control networking system in a m...
research
06/08/2018

A SDN-based Flexible System for On-the-Fly Monitoring and Treatment of Security Events

The Software Defined Networking (SDN) paradigm decouples control and dat...
research
04/08/2018

The Challenges in SDN/ML Based Network Security : A Survey

Machine Learning is gaining popularity in the network security domain as...
research
07/27/2019

Q-MIND: Defeating Stealthy DoS Attacks in SDN with a Machine-learning based Defense Framework

Software Defined Networking (SDN) enables flexible and scalable network ...
research
04/01/2018

Software-Defined Network (SDN) Data Plane Security: Issues, Solutions and Future Directions

Software-Defined Network (SDN) radically changes the network architectur...
research
12/28/2018

Do we have the time for IRM?: Service denial attacks and SDN-based defences

Distributed sensor networks such as IoT deployments generate large quant...

Please sign up or login with your details

Forgot password? Click here to reset