Skip to main navigation Skip to search Skip to main content

A Filtering Model for Evidence Gathering in an SDN-Oriented Digital Forensic and Incident Response Context

  • Maria B. Jimenez
  • , David Fernandez*
  • , Jorge Eduardo Rivadeneira
  • , Ricardo Flores-Moyano
  • *Corresponding author for this work
  • Technical University of Madrid
  • University of Coimbra

Research output: Contribution to journalArticlepeer-review

4 Scopus citations

Abstract

Software-defined networking (SDN) architecture enables flexible and centralized network management from the controller, making it increasingly attractive in deploying telecommunications services. However, despite the many benefits of SDN, the vulnerabilities inherent in its architecture must be considered, and potential attacks must be discarded. When this occurs, not only the technical areas are interested in the source of the problem, but also the organizational areas, since attacks can violate terms of service and lead to legal actions. Despite the shared interest in cybersecurity event information, forensics and incident response processes often operate independently, impacting the root cause determination. Considering this concern, an architectural evolution for digital forensics and incident response (DFIR) management is introduced. This paper presents an event filtering model that serves as a trigger for initialing the DFIR process, which involves the detection of unusual traffic and unexpected behavior of SDN elements. The proposal applies artificial intelligence technology and showcases the performance of the model and the presentation of a proprietary dataset obtained from OpenFlow traffic.

Original languageEnglish
Pages (from-to)75792-75808
Number of pages17
JournalIEEE Access
Volume12
DOIs
StatePublished - 2024

Keywords

  • DDoS attacks
  • SDN DFIR
  • SDN attacks
  • SDN cybersecurity
  • SDN dataset
  • SDN forensics
  • artificial intelligence algorithms

Fingerprint

Dive into the research topics of 'A Filtering Model for Evidence Gathering in an SDN-Oriented Digital Forensic and Incident Response Context'. Together they form a unique fingerprint.

Cite this