A Framework for SDN Forensic Readiness and Cybersecurity Incident Response

被引:2
|
作者
Jimenez, Maria B. [1 ]
Fernandez, David [1 ]
机构
[1] Univ Politecn Madrid, Dept Telemat Engn, Madrid, Spain
关键词
SDN Forensics; Evidence; Digital Forensic; SDN Incident Response; SDN Security; SDN Framework;
D O I
10.1109/NFV-SDN56302.2022.9974648
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
SDN represents a significant advance for the telecom world, since the decoupling of the control and data planes offers numerous advantages in terms of management dynamism and programmability, mainly due to its software-based centralized control. Unfortunately, these features can be exploited by malicious entities, who take advantage of the centralized control to extend the scope and consequences of their attacks. When this happens, both the legal and network technical fields are concerned with gathering information that will lead them to the root cause of the problem. Although forensics and incident response processes share their interest in the event information, both operate in isolation due to the conceptual and pragmatic challenges of integrating them into SDN environments, which impacts on the resources and time required for information analysis. Given these limitations, the current work focuses on proposing a framework for SDNs that combines the above approaches to optimize the resources to deliver evidence, incorporate incident response activation mechanisms, and generate assumptions about the possible origin of the security problem.
引用
收藏
页码:112 / 116
页数:5
相关论文
共 50 条
  • [31] Action Bias and the Two Most Dangerous Words in Cybersecurity Incident Response An Argument for More Measured Incident Response
    Dykstra, Josiah
    Met, Jamie
    Backert, Nicole
    Mattie, Rebecca
    Hough, Douglas
    IEEE SECURITY & PRIVACY, 2022, 20 (03) : 102 - 106
  • [32] Cybersecurity Readiness for Automated Vehicles
    Khan, Shah Khalid
    Shiwakoti, Nirajan
    Stasinopoulos, Peter
    Warren, Matthew
    2022 INTERNATIONAL CONFERENCE ON FRONTIERS OF ARTIFICIAL INTELLIGENCE AND MACHINE LEARNING, FAIML, 2022, : 7 - 12
  • [33] A natural human language framework for digital forensic readiness in the public cloud
    Baror, Stacey O.
    Venter, Hein S.
    Adeyemi, Richard
    AUSTRALIAN JOURNAL OF FORENSIC SCIENCES, 2021, 53 (05) : 566 - 591
  • [34] A Conceptual Framework to Determine the Digital Forensic Readiness of a Cloud Service Provider
    Makutsoane, Mpho Percy
    Leonard, Awie
    2014 PORTLAND INTERNATIONAL CONFERENCE ON MANAGEMENT OF ENGINEERING & TECHNOLOGY (PICMET), 2014, : 3313 - 3321
  • [35] Cybersecurity Incident Response for the Sub-Saharan African Aviation Industry
    Lekota, Faith
    Coetzee, Marijke
    PROCEEDINGS OF THE 14TH INTERNATIONAL CONFERENCE ON CYBER WARFARE AND SECURITY (ICCWS 2019), 2019, : 536 - 545
  • [36] Demystifying analytical information processing capability: The case of cybersecurity incident response
    Naseer, Humza
    Maynard, Sean B.
    Desouza, Kevin C.
    DECISION SUPPORT SYSTEMS, 2021, 143
  • [37] Demystifying analytical information processing capability: The case of cybersecurity incident response
    Naseer, Humza
    Maynard, Sean B.
    Desouza, Kevin C.
    Decision Support Systems, 2021, 143
  • [38] A GRReat Framework for Incident Response in Healthcare
    Acharya, Subrata
    Glenn, William
    Carr, Matthew
    PROCEEDINGS 2015 IEEE INTERNATIONAL CONFERENCE ON BIOINFORMATICS AND BIOMEDICINE, 2015, : 776 - 778
  • [39] The corporate incident response framework (CIRF)
    Pieterse, Theron
    2011 IST-Africa Conference Proceedings, IST 2011, 2011,
  • [40] Linking Cybersecurity and Accounting: An Event, Impact, Response Framework
    Janvrin, Diane J.
    Wang, Tawei
    ACCOUNTING HORIZONS, 2022, 36 (04) : 67 - 112