Modelirovanie i Analiz Informatsionnykh Sistem
RUS  ENG    JOURNALS   PEOPLE   ORGANISATIONS   CONFERENCES   SEMINARS   VIDEO LIBRARY   PACKAGE AMSBIB  
General information
Latest issue
Archive
Impact factor

Search papers
Search references

RSS
Latest issue
Current issues
Archive issues
What is RSS



Model. Anal. Inform. Sist.:
Year:
Volume:
Issue:
Page:
Find






Personal entry:
Login:
Password:
Save password
Enter
Forgotten password?
Register


Modelirovanie i Analiz Informatsionnykh Sistem, 2019, Volume 26, Number 1, Pages 134–145
DOI: https://doi.org/10.18255/1818-1015-2019-1-134-145
(Mi mais669)
 

Computer Networks and Communications

«Common criteria» and software defined network security

A. N. Petukhova, P. L. Pilyuginb

a National Research University of Electronic Technology – MIET, Bld. 1, Shokin Square, Zelenograd, Moscow, 124498, Russia
b Lomonosov Moscow State University, GSP-1, Leninskie Gory, Moscow, 119991, Russia
References:
Abstract: «Common criteria» (ISO 15408) is a universally recognized and broadly applicable approach to information security solutions management and evaluation. «Common criteria» leans on developing a shared conceptual basis for key security solution modules including protection profiles and security targets. Conceptual basis development implies defining the following elements: security objectives and assumptions (for the environment and the object), threats and security policies, as well as functional and assurance requirements. The specifics of SDN (software defined network) security solutions is largely driven by fundamental architectural principles of SDN technology itself — primarily by the separation of control and data flows, — and by conditions imposed by Open Flow protocol application. However, proactive (threats and policies), passive (objectives and assumptions) and reactive (requirements) aspects of security management remain highly relevant for this type of security solutions. This paper discusses the Common Criteria application specifics for assessing the SDN security and practical MTUCI (Moscow Technical University of Communications and Informatics) experience in the development of the protection profile. A new class of network attacks on SDN switches and controllers can involve either data or control components. In addition to traditional vulnerabilities, centralization of management functions paves way for new security threats by isolating controller activity and administrative message exchange. Therefore, identifying and analyzing threats, policies and requirements specific to SDN control module security becomes an emerging priority.
Keywords: security of software defined networks, general criteria, security profile.
Funding agency
The work was supported by MTUCI (Moscow Technical University of Communications and Informatics) rectorate: Erokhin S., Leokhin Yu. and Mukhanov A., and with funding from the MTUCI, in the direction of «Security of critical information infrastructures».
Received: 10.01.2019
Bibliographic databases:
Document Type: Article
UDC: 004.056.5(076)
Language: Russian
Citation: A. N. Petukhov, P. L. Pilyugin, “«Common criteria» and software defined network security”, Model. Anal. Inform. Sist., 26:1 (2019), 134–145
Citation in format AMSBIB
\Bibitem{PetPil19}
\by A.~N.~Petukhov, P.~L.~Pilyugin
\paper «Common criteria» and software defined network security
\jour Model. Anal. Inform. Sist.
\yr 2019
\vol 26
\issue 1
\pages 134--145
\mathnet{http://mi.mathnet.ru/mais669}
\crossref{https://doi.org/10.18255/1818-1015-2019-1-134-145}
\elib{https://elibrary.ru/item.asp?id=37069563}
Linking options:
  • https://www.mathnet.ru/eng/mais669
  • https://www.mathnet.ru/eng/mais/v26/i1/p134
  • Citing articles in Google Scholar: Russian citations, English citations
    Related articles in Google Scholar: Russian articles, English articles
    Ìîäåëèðîâàíèå è àíàëèç èíôîðìàöèîííûõ ñèñòåì
    Statistics & downloads:
    Abstract page:221
    Full-text PDF :204
    References:28
     
      Contact us:
     Terms of Use  Registration to the website  Logotypes © Steklov Mathematical Institute RAS, 2024