Optimal network reconfiguration for software defined networks using shuffle-based online MTD

Jin Bum Hong, Seunghyun Yoon, Hyuk Lim, Dong Seong Kim

Research output: Chapter in Book/Conference paperConference paperpeer-review

33 Citations (Scopus)

Abstract

A Software Defined Network (SDN) provides functionalities for modifying network configurations. To enhance security, Moving Target Defense (MTD) techniques are deployed in the networks to continuously change the attack surface. In this paper, we realize an MTD system by exploiting the SDN functionality to optimally reconfigure the network topology. We introduce a novel problem Shuffle Assignment Problem (SAP), the reconfiguration of a network topology for enhanced security, and we show how to compute the optimal solution for small-sized networks and the near-optimal solution for large-sized networks using a heuristic method. In addition, we propose a shuffle-based online MTD mechanism, which periodically reconfigures the network topology to continuously change the attack surface. This mechanism also selects an optimal countermeasure using our proposed topological distance metric in real-time when an attack is detected. We demonstrate the feasibility and the effectiveness of our proposed solutions through experimental analysis on an SDN testbed and simulations.

Original languageEnglish
Title of host publicationProceedings - 2017 IEEE 36th International Symposium on Reliable Distributed Systems, SRDS 2017
Place of PublicationUSA
PublisherIEEE, Institute of Electrical and Electronics Engineers
Pages234-243
Number of pages10
Volume2017-September
ISBN (Electronic)9781538616796
DOIs
Publication statusPublished - 13 Oct 2017
Externally publishedYes
Event36th IEEE International Symposium on Reliable Distributed Systems, SRDS 2017 - Hong Kong, Hong Kong
Duration: 26 Sept 201729 Sept 2017

Conference

Conference36th IEEE International Symposium on Reliable Distributed Systems, SRDS 2017
Country/TerritoryHong Kong
CityHong Kong
Period26/09/1729/09/17

Fingerprint

Dive into the research topics of 'Optimal network reconfiguration for software defined networks using shuffle-based online MTD'. Together they form a unique fingerprint.

Cite this