Visible to the public SDN Based Scalable MTD Solution in Cloud Network

TitleSDN Based Scalable MTD Solution in Cloud Network
Publication TypeConference Paper
Year of Publication2016
AuthorsChowdhary, Ankur, Pisharody, Sandeep, Huang, Dijiang
Conference NameProceedings of the 2016 ACM Workshop on Moving Target Defense
PublisherACM
Conference LocationNew York, NY, USA
ISBN Number978-1-4503-4570-5
Keywordsmoving target defenses, pubcrawl, Scalability, security scalability
Abstract

Software-Defined Networking (SDN) has emerged as a framework for centralized command and control in cloud data centric environments. SDN separates data and control plane, which provides network administrator better visibility and policy enforcement capability compared to traditional networks. The SDN controller can assess reachability information of all the hosts in a network. There are many critical assets in a network which can be compromised by a malicious attacker through a multistage attack. Thus we make use of centralized controller to assess the security state of the entire network and pro-actively perform attack analysis and countermeasure selection. This approach is also known as Moving Target Defense (MTD). We use the SDN controller to assess the attack scenarios through scalable Attack Graphs (AG) and select necessary countermeasures to perform network reconfiguration to counter network attacks. Moreover, our framework has a comprehensive conflict detection and resolution module that ensures that no two flow rules in a distributed SDN-based cloud environment have conflicts at any layer; thereby assuring consistent conflict-free policy implementation and preventing information leakage.

URLhttp://doi.acm.org/10.1145/2995272.2995274
DOI10.1145/2995272.2995274
Citation Keychowdhary_sdn_2016