A Framework for SDN Forensic Readiness and Cybersecurity Incident Response

被引:2
|
作者
Jimenez, Maria B. [1 ]
Fernandez, David [1 ]
机构
[1] Univ Politecn Madrid, Dept Telemat Engn, Madrid, Spain
关键词
SDN Forensics; Evidence; Digital Forensic; SDN Incident Response; SDN Security; SDN Framework;
D O I
10.1109/NFV-SDN56302.2022.9974648
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
SDN represents a significant advance for the telecom world, since the decoupling of the control and data planes offers numerous advantages in terms of management dynamism and programmability, mainly due to its software-based centralized control. Unfortunately, these features can be exploited by malicious entities, who take advantage of the centralized control to extend the scope and consequences of their attacks. When this happens, both the legal and network technical fields are concerned with gathering information that will lead them to the root cause of the problem. Although forensics and incident response processes share their interest in the event information, both operate in isolation due to the conceptual and pragmatic challenges of integrating them into SDN environments, which impacts on the resources and time required for information analysis. Given these limitations, the current work focuses on proposing a framework for SDNs that combines the above approaches to optimize the resources to deliver evidence, incorporate incident response activation mechanisms, and generate assumptions about the possible origin of the security problem.
引用
收藏
页码:112 / 116
页数:5
相关论文
共 50 条
  • [41] Digital Forensics Readiness in Big Data Networks: A Novel Framework and Incident Response Script for Linux-Hadoop Environments
    Mpungu, Cephas
    George, Carlisle
    Mapp, Glenford
    APPLIED SYSTEM INNOVATION, 2024, 7 (05)
  • [42] Enhancing incident readiness
    Technology Risk Consulting Services, LLC, United States
    SSA J, 4 (19-22):
  • [43] Using Digital Forensic Readiness Model to Increase the Forensic Readiness of a Computer System
    Kazadi, Jeff Mutunda
    Jazri, Husin
    2015 INTERNATIONAL CONFERENCE ON EMERGING TRENDS IN NETWORKS AND COMPUTER COMMUNICATIONS (ETNCC), 2015, : 131 - 137
  • [44] Contextualising Cybersecurity Readiness in South Africa
    Veerasamy, Namosha
    Mashiane, Thulani
    Pillay, Kiru
    PROCEEDINGS OF THE 14TH INTERNATIONAL CONFERENCE ON CYBER WARFARE AND SECURITY (ICCWS 2019), 2019, : 467 - 475
  • [45] Digital Forensic Readiness Framework Based on Behavioral-Biometrics for User Attribution
    Ikuesan, Adeyemi R.
    Venter, Hein S.
    2017 IEEE CONFERENCE ON APPLICATION, INFORMATION AND NETWORK SECURITY (AINS), 2017, : 54 - 59
  • [46] SoK: Applications and Challenges of using Recommender Systems in Cybersecurity Incident Handling and Response
    Husak, Martin
    Cermak, Milan
    PROCEEDINGS OF THE 17TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY, ARES 2022, 2022,
  • [47] A Framework for Incident Response: The Case of UUM ERT
    Taib, Che Azlan
    Hassan, Mohamad Ghozali
    Lazim, Halim Mad
    PROCEEDINGS OF THE 4TH INTERNATIONAL CASE STUDY CONFERENCE (ICSC) 2019, 2019, : 243 - 249
  • [48] A Framework for Incident Response in Industrial Control Systems
    Schlegel, Roman
    Hristova, Ana
    Obermeier, Sebastian
    2015 12TH INTERNATIONAL JOINT CONFERENCE ON E-BUSINESS AND TELECOMMUNICATIONS (ICETE), VOL 4, 2015, : 178 - 185
  • [49] A framework for incident response management in the petroleum industry
    Jaatun, Martin Gilje
    Albrechtsen, Eirik
    Line, Maria B.
    Tondel, Inger Anne
    Longva, Odd Helge
    INTERNATIONAL JOURNAL OF CRITICAL INFRASTRUCTURE PROTECTION, 2009, 2 (1-2) : 26 - 37
  • [50] A Virtual Reality Framework for Training Incident First Responders and Digital Forensic Investigators
    Karabiyik, Umit
    Mousas, Christos
    Sirota, Daniel
    Iwai, Takahide
    Akdere, Mesut
    ADVANCES IN VISUAL COMPUTING, ISVC 2019, PT II, 2019, 11845 : 469 - 480