EVHS - Elastic Virtual Honeypot System for SDNFV-Based Networks

Nguyen Canh Thang(1*), Minho Park(2), Yang Ick Joo(3)
(1) Soongsil University
(2) 
(3) 
(*) Corresponding Author

Abstract

The SDNFV-based network has leveraged the advantages of software-defined networking (SDN) and network-function virtualization (NFV) to become the most prominent network architecture. However, with the advancement of the SDNFV-based network, more attack types have emerged. This research focuses on one of the methods (use of the honeypot system) of preventing these attacks on the SDNFV-based network. We introduce an SDNFV-based elastic virtual honeypot system (EVHS), which not only resolves problems of other current honeypot systems but also employs a new approach to efficiently manage and control honeypots. It uses a network-intrusion-detection system (NIDS) at the border of the network to detect attacks, leverages the advantages of SDN and NFV to flexibly generate honeypots, and connects attackers to these honeypots by using a moving-target defense mechanism. Furthermore, we optimize the system to efficiently reuse the available honeypots after the attacks are handled. Experimental results validate that the proposed system is a flexible and efficient approach to manage and provide virtual honeypots in the SDNFV-based network; the system can also resolve the problems encountered by current honeypot systems.

Article Statistic

Abstract view : 21 times
PDF views : 11 times

How To Cite This :

Refbacks

  • There are currently no refbacks.


Institute of Computing, International Journal of Communication Networks and Information Security (IJCNIS)               ISSN: 2073-607X (Online)