UNSW, Sydney
Securing Software-Defined Network Enabled Enterprises Against Insider Threats
Abstract
dc:descriptionInsider threats are among the most challenging cyber security issues for enterprises, and even the world's most protected organizations have not been immune to them. In the first part of this thesis, considering the recent paradigm shift to Software-Defined Networks (SDNs) and its compelling enterprise benefits, we devise three novel solutions to protect an organization against insiders with access to the network infrastructure. Our first solution is an SDN controller-agnostic Intrusion Prevention System (IPS) capable of detecting malicious forwarding devices independent of the underlying hardware and software. We leverage the SDN capabilities to retrieve the actual and expected packet trajectories and devise algorithms to systematically scan the network, locate malicious devices, detect their specific malicious behavior and protect the network according to pre-defined policies. We then improve this solution by enhancing its core functionalities including an advanced customizable data plane scanning algorithm and a more efficient packet tracking mechanism reducing the detection time by up to 50\%. Third, we design the first IPS capable of detecting a malicious SDN controller by analyzing the data plane trajectories, which in extreme cases, can take over the SDN controller altogether. In the second part of the thesis, we integrate our earlier work as part of a novel contextual access control framework against insiders with access to both organization's data and network infrastructure. The proposed solution has two key characteristics. First, it grants access authorizations based on the contextual information extracted through analysis of the network traffic. Hence, compared to related work, removing the need for additional verification mechanism or input from the user's device integrated sensors. Second, it incorporates feedback from the network infrastructure IPS in the access authorization process. Leveraging the SDN capabilities, our solution also enhances the access policy enforcement by dynamically applying restrictions both at host-level and network-level creating an inter-layer and inter-domain access enforcement model. Furthermore, on the user-side side access enforcement can be custom defined at function-level granularity for the different data segments depending on the context status. Compared to the existing solutions, our evaluation results indicate a much higher accuracy and better performance.
Degree
thesis:*- Grantor dc:publisher
- UNSW, Sydney
- Year dc:date
- 2018
Author and committee
dc:creator, dc:contributor.*- Author dc:creator
-
- Shaghaghi, Arash
Subjects
dc:subject × 4Rights
dc:rights- Statement dc:rights
-
- open access
- CC BY-NC-ND 3.0
- free_to_read
- Licence
- Language dc:language
- EN
Identifiers
dc:identifier.*- Identifier
- https://doi.org/10.26190/unsworks/3636
- OAI identifier oai:identifier
- oai:unsworks.library.unsw.edu.au:1959.4/61502