Visible to the public HogMap: Using SDNs to Incentivize Collaborative Security Monitoring

TitleHogMap: Using SDNs to Incentivize Collaborative Security Monitoring
Publication TypeConference Paper
Year of Publication2016
AuthorsPan, Xiang, Yegneswaran, Vinod, Chen, Yan, Porras, Phillip, Shin, Seungwon
Conference NameProceedings of the 2016 ACM International Workshop on Security in Software Defined Networks & Network Function Virtualization
PublisherACM
Conference LocationNew York, NY, USA
ISBN Number978-1-4503-4078-6
Keywordscyber threat intelligence, honeygrid, honeynet, marketplace, pubcrawl, Resiliency, Scalability, SDN, SDN security, threat mitigation
Abstract

Cyber Threat Intelligence (CTI) sharing facilitates a comprehensive understanding of adversary activity and enables enterprise networks to prioritize their cyber defense technologies. To that end, we introduce HogMap, a novel software-defined infrastructure that simplifies and incentivizes collaborative measurement and monitoring of cyber-threat activity. HogMap proposes to transform the cyber-threat monitoring landscape by integrating several novel SDN-enabled capabilities: (i) intelligent in-place filtering of malicious traffic, (ii) dynamic migration of interesting and extraordinary traffic and (iii) a software-defined marketplace where various parties can opportunistically subscribe to and publish cyber-threat intelligence services in a flexible manner. We present the architectural vision and summarize our preliminary experience in developing and operating an SDN-based HoneyGrid, which spans three enterprises and implements several of the enabling capabilities (e.g., traffic filtering, traffic forwarding and connection migration). We find that SDN technologies greatly simplify the design and deployment of such globally distributed and elastic HoneyGrids.

URLhttp://doi.acm.org/10.1145/2876019.2876023
DOI10.1145/2876019.2876023
Citation Keypan_hogmap:_2016