摘要: |
Software-defined networks (SDNs) are susceptible to a wide variety of known and unknown cyberattacks. With adversaries that are capable ofgenerating automated attacks at high pace and volume, as well as the possibility of system failures that can crop up at any time, it can be difficultfor human cybersecurity experts to keep up with the necessary recovery and defense tasks. In this paper, we introduce ACRS4SDN, a system tomonitor for, and quickly respond to attacks and failures that may occur in a SDN. An integral part of ACRS4SDN is its ability to autonomouslyrecover using automated acting and planning, and it does so using a technique called hierarchical refinement. ACRS4SDN recovers a targetsystem from faults and attacks by online planning using attack recovery procedures written as a hierarchical operational model. The autonomousresponses orchestrated by ACRS4SDN considerably narrow the gap between cyberattacks and cyber defense, in terms of speed and volume, andwe validate this through experimental results on a real SDN across a series of cyberattack scenarios. |