论文标题

使用软件定义网络的威胁分析框架

A Framework for Threats Analysis Using Software-Defined Networking

论文作者

Moldovan, Francisc, Oprisa, Ciprian

论文摘要

分析网络威胁的能力在安全研究中非常重要。传统方法,涉及沙箱技术的方法仅限于模拟单个主机,而缺少本地网络攻击。通过设计一个使用软件定义的网络来模拟任意网络的威胁分析框架来解决此问题。提出的系统具有灵活性,使安全研究人员可以定义能够捕获恶意动作并之后恢复到初始状态的虚拟网络。描述了框架设计和常见用法方案。通过提供此框架,我们旨在减轻打击网络威胁的分析工作。

The ability to analyze network threats is very important in security research. Traditional approaches, involving sandboxing technology are limited to simulating a single host, missing local network attacks. This issue is addressed by designing a threat analysis framework that uses software-defined networking for simulating arbitrary networks. The presented system offers flexibility, allowing a security researcher to define a virtual network that is able to capture malicious actions and to be restored to the initial state afterwards. Both the framework design and common usage scenarios are described. By providing this framework, we aim to ease the analysis effort in combating cyberthreats.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源