4.7 Article

Citadel: Cyber threat intelligence assisted defense system for software-defined networks

Journal

COMPUTER NETWORKS
Volume 191, Issue -, Pages -

Publisher

ELSEVIER
DOI: 10.1016/j.comnet.2021.108013

Keywords

Cyber security; Cyber defense; Cyber threat intelligence; CTI; Software-defined networking; SDN; Network function virtualization; NFV; Service function chaining; SFC

Ask authors/readers for more resources

This paper introduces a new network security system Citadel, utilizing cyber threat intelligence and virtualization technologies for automated, flexible, and effective network defense. By analyzing CTI data, extracting attacker models, and designing corresponding security services, Citadel provides a proactive defense against network threats.
Defending networks is becoming more challenging due to the growing number and variety of cyber threats. On the other hand, network security professionals have new technologies and tools at their disposal. This paper focuses on a few of these technologies and investigates new ways to take advantage of them. To this end, we present Citadel, a novel security system utilizing cyber threat intelligence (CTI) to construct automated defense solutions in software-defined networking (SDN) environments. Citadel also incorporates network function virtualization (NFV) and service function chaining (SFC) to achieve flexible, cost-efficient, and proactive network defense. We examine CTI data to extract common attacker models and design security services as virtual network functions chained together using SFC to counter these threats. The modular and extensible nature of Citadel makes it suitable for incremental deployment in networks. Besides, we propose a new CTI data model to use as an extension of the existing CTI models for better compatibility with automated network defense. Extensive evaluations demonstrate that our proposals are applicable and effectively facilitate the management of agile defense in SDN/NFV-enabled networks.

Authors

I am an author on this paper
Click your name to claim this paper and add it to your profile.

Reviews

Primary Rating

4.7
Not enough ratings

Secondary Ratings

Novelty
-
Significance
-
Scientific rigor
-
Rate this paper

Recommended

No Data Available
No Data Available