A Novel Approach for Bridging the Gap Between SDN and MITRE for Agile Incident Response
摘要
The growing complexity of potential attacks in network infrastructure demands advanced incident response (IR) techniques. With organization adopting the Software-Defined Networks the response capabilities can be improved to a greater extend. SDN’s centralized control is utilized in this process. However the lacking of a list of possible defense mechanisms in the SDN, effects the swift respondence against the occurrence of a security incident. To address this challenge, we studied the MITRE D3FEND knowledge base, which provides various standard defense mechanisms. Later, within the knowledge base the defense mechanisms that can be implemented in SDN were identified. A valid list of possible implementable defense mechanisms in SDN was created. With the help of the developed implementer tool ANTq, which runs on top of the Ryu controller the suggested MITRE defense mechanisms were automatically implemented.