Skip to main navigation Skip to search Skip to main content

Adaptive policy-driven attack mitigation in SDN

  • Université Paris-Saclay
  • Université de Lille

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

This paper presents a dynamic policy enforcement mechanism that allows ISPs to specify security policies to mitigate the impact of network attacks by taking into account the specific requirements of their customers. The proposed policybased management framework leverages the central network view provided by the Software-Defined Networking (SDN) paradigm. One of the major objectives of such a framework is to achieve fine-grained and automated attack mitigation in the ISP network, ultimately reducing the impact of attack and collateral damage to the customer networks. To evaluate the feasibility and effectiveness of framework, we develop a prototype that serves for one ISP and three customers. The experimental results demonstrate that our framework can successfully reduce the collateral damage on a customer network caused by the attack traffic targeting another customer network. More interestingly, the framework can provide rapid response and mitigate the attack in a very short time.

Original languageEnglish
Title of host publicationProceedings of the 1st International Workshop on Security and Dependability of Multi-Domain Infrastructures, XDOM0 2017 - Co-located with European Conference on Computer Systems, EuroSys 2017
PublisherAssociation for Computing Machinery
ISBN (Electronic)9781450349376
DOIs
Publication statusPublished - 23 Apr 2017
Externally publishedYes
Event1st International Workshop on Security and Dependability of Multi-Domain Infrastructures, XDOM0 2017, co-located with EuroSys 2017 - Belgrade, Serbia
Duration: 23 Apr 2017 → …

Publication series

NameProceedings of the 1st International Workshop on Security and Dependability of Multi-Domain Infrastructures, XDOM0 2017 - Co-located with European Conference on Computer Systems, EuroSys 2017

Conference

Conference1st International Workshop on Security and Dependability of Multi-Domain Infrastructures, XDOM0 2017, co-located with EuroSys 2017
Country/TerritorySerbia
CityBelgrade
Period23/04/17 → …

Keywords

  • Policy management
  • SDN
  • Security policy

Fingerprint

Dive into the research topics of 'Adaptive policy-driven attack mitigation in SDN'. Together they form a unique fingerprint.

Cite this