A Framework for SDN Forensic Readiness and Cybersecurity Incident Response

被引:2
|
作者
Jimenez, Maria B. [1 ]
Fernandez, David [1 ]
机构
[1] Univ Politecn Madrid, Dept Telemat Engn, Madrid, Spain
关键词
SDN Forensics; Evidence; Digital Forensic; SDN Incident Response; SDN Security; SDN Framework;
D O I
10.1109/NFV-SDN56302.2022.9974648
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
SDN represents a significant advance for the telecom world, since the decoupling of the control and data planes offers numerous advantages in terms of management dynamism and programmability, mainly due to its software-based centralized control. Unfortunately, these features can be exploited by malicious entities, who take advantage of the centralized control to extend the scope and consequences of their attacks. When this happens, both the legal and network technical fields are concerned with gathering information that will lead them to the root cause of the problem. Although forensics and incident response processes share their interest in the event information, both operate in isolation due to the conceptual and pragmatic challenges of integrating them into SDN environments, which impacts on the resources and time required for information analysis. Given these limitations, the current work focuses on proposing a framework for SDNs that combines the above approaches to optimize the resources to deliver evidence, incorporate incident response activation mechanisms, and generate assumptions about the possible origin of the security problem.
引用
收藏
页码:112 / 116
页数:5
相关论文
共 50 条
  • [1] An Engineering Process Framework for Cybersecurity Incident Response Assessment
    Freas, Robert L.
    Adair, Heather F.
    Hammad, Eman
    2022 5TH IEEE CONFERENCE ON DEPENDABLE AND SECURE COMPUTING (IEEE DSC 2022), 2022,
  • [2] Cybersecurity incident response
    Garzón, Fabian
    ISACA Journal, 2020, 4 : 49 - 54
  • [3] CFRF: Cloud Forensic Readiness Framework - A Dependable Framework for Forensic Readiness in Cloud Computing Environment
    Bhatia, Sugandh
    Malhotra, Jyoteesh
    INNOVATIVE DATA COMMUNICATION TECHNOLOGIES AND APPLICATION, 2020, 46 : 765 - 775
  • [4] Forensic Readiness of Smart Buildings Preconditions for Subsequent Cybersecurity Tests
    Bajramovic, Edita
    Waedt, Karl
    Ciriello, Antonio
    Gupta, Deeksha
    IEEE SECOND INTERNATIONAL SMART CITIES CONFERENCE (ISC2 2016), 2016, : 126 - 131
  • [5] A Framework for Cloud Forensic Readiness in Organizations
    Alenezi, Ahmed
    Hussein, Raid Khalid
    Walters, Robert J.
    Wills, Gary B.
    2017 5TH IEEE INTERNATIONAL CONFERENCE ON MOBILE CLOUD COMPUTING, SERVICES, AND ENGINEERING (MOBILECLOUD), 2017, : 199 - 204
  • [6] A Case for a Dynamic Approach to Digital Forensic Readiness in an SDN Platform
    Munkhondya, Howard
    Ikuesan, Adeyemi R.
    Venter, Hein S.
    PROCEEDINGS OF THE 15TH INTERNATIONAL CONFERENCE ON CYBER WARFARE AND SECURITY (ICCWS 2020), 2020, : 584 - 593
  • [7] A Filtering Model for Evidence Gathering in an SDN-Oriented Digital Forensic and Incident Response Context
    Jimenez, Maria B.
    Fernandez, David
    Rivadeneira, Jorge Eduardo
    Flores-Moyano, Ricardo
    IEEE ACCESS, 2024, 12 : 75792 - 75808
  • [8] ARCS: Adaptive Reinforcement Learning Framework for Automated Cybersecurity Incident Response Strategy Optimization
    Ren, Shaochen
    Jin, Jianian
    Niu, Guanchong
    Liu, Yang
    APPLIED SCIENCES-BASEL, 2025, 15 (02):
  • [9] A Theoretical Framework for Organizational Network Forensic Readiness
    Endicott-Popovsky, Barbara
    Frincke, Deborah A.
    Taylor, Carol A.
    JOURNAL OF COMPUTERS, 2007, 2 (03) : 1 - 11
  • [10] TOWARDS A SYSTEMIC FRAMEWORK FOR DIGITAL FORENSIC READINESS
    Elyas, Mohamed
    Maynard, Sean B.
    Ahviad, Atif
    Lonie, Andrew
    JOURNAL OF COMPUTER INFORMATION SYSTEMS, 2014, 54 (03) : 97 - 105