SAND: Semi-Automated Adaptive Network Defense Via Programmable Rule Generation and Deployment

Chen Haoyu,Zou Deqing,Jin Hai,Xu Shouhuai,Yuan Bin
DOI: https://doi.org/10.1007/s11432-020-3193-2
2022-01-01
Science China Information Sciences
Abstract:Cyber security is dynamic as defenders often need to adapt their defense postures. The state-ofthe-art is that the adaptation of network defense is done manually(i.e., tedious and error-prone). The ideal solution is to automate adaptive network defense, which is however a difficult problem. As a first step towards automation, we propose investigating how to attain semi-automated adaptive network defense(SAND). We propose an approach extending the architecture of software-defined networking, which is centered on providing defenders with the capability to program the generation and deployment of dynamic defense rules enforced by network defense tools. We present the design and implementation of SAND, as well as the evaluation of the prototype implementation. Experimental results show that SAND can achieve agile and effective dynamic adaptations of defense rules(less than 15 ms on average for each operation), while only incurring a small performance overhead.
What problem does this paper attempt to address?