TY - JOUR
T1 - A security assessment mechanism for software-defined networking-based mobile networks
AU - Luo, Shibo
AU - Dong, Mianxiong
AU - Ota, Kaoru
AU - Wu, Jun
AU - Li, Jianhua
N1 - Publisher Copyright:
© 2015 by the authors; licensee MDPI, Basel, Switzerland.
PY - 2015/12/17
Y1 - 2015/12/17
N2 - Software-Defined Networking-based Mobile Networks (SDN-MNs) are considered the future of 5G mobile network architecture. With the evolving cyber-attack threat, security assessments need to be performed in the network management. Due to the distinctive features of SDN-MNs, such as their dynamic nature and complexity, traditional network security assessment methodologies cannot be applied directly to SDN-MNs, and a novel security assessment methodology is needed. In this paper, an effective security assessment mechanism based on attack graphs and an Analytic Hierarchy Process (AHP) is proposed for SDN-MNs. Firstly, this paper discusses the security assessment problem of SDN-MNs and proposes a methodology using attack graphs and AHP. Secondly, to address the diversity and complexity of SDN-MNs, a novel attack graph definition and attack graph generation algorithm are proposed. In order to quantify security levels, the Node Minimal Effort (NME) is defined to quantify attack cost and derive system security levels based on NME. Thirdly, to calculate the NME of an attack graph that takes the dynamic factors of SDN-MN into consideration, we use AHP integrated with the Technique for Order Preference by Similarity to an Ideal Solution (TOPSIS) as the methodology. Finally, we offer a case study to validate the proposed methodology. The case study and evaluation show the advantages of the proposed security assessment mechanism.
AB - Software-Defined Networking-based Mobile Networks (SDN-MNs) are considered the future of 5G mobile network architecture. With the evolving cyber-attack threat, security assessments need to be performed in the network management. Due to the distinctive features of SDN-MNs, such as their dynamic nature and complexity, traditional network security assessment methodologies cannot be applied directly to SDN-MNs, and a novel security assessment methodology is needed. In this paper, an effective security assessment mechanism based on attack graphs and an Analytic Hierarchy Process (AHP) is proposed for SDN-MNs. Firstly, this paper discusses the security assessment problem of SDN-MNs and proposes a methodology using attack graphs and AHP. Secondly, to address the diversity and complexity of SDN-MNs, a novel attack graph definition and attack graph generation algorithm are proposed. In order to quantify security levels, the Node Minimal Effort (NME) is defined to quantify attack cost and derive system security levels based on NME. Thirdly, to calculate the NME of an attack graph that takes the dynamic factors of SDN-MN into consideration, we use AHP integrated with the Technique for Order Preference by Similarity to an Ideal Solution (TOPSIS) as the methodology. Finally, we offer a case study to validate the proposed methodology. The case study and evaluation show the advantages of the proposed security assessment mechanism.
KW - 5G
KW - Analytic hierarchy process
KW - Attack graph
KW - Security assessment
KW - Software-defined networking based mobile networks
UR - http://www.scopus.com/inward/record.url?scp=84950249299&partnerID=8YFLogxK
UR - http://www.scopus.com/inward/citedby.url?scp=84950249299&partnerID=8YFLogxK
U2 - 10.3390/s151229887
DO - 10.3390/s151229887
M3 - Article
AN - SCOPUS:84950249299
SN - 1424-8220
VL - 15
SP - 31843
EP - 31858
JO - Sensors (Switzerland)
JF - Sensors (Switzerland)
IS - 12
ER -