Automated Detection of Configured SDN Security Policies for ICS Networks

Sixth Annual Industrial Control System Security (ICSS) Workshop(2020)

引用 0|浏览0
暂无评分
摘要
The deployment of a security on a network infrastructure requires the specification and enforcement of security policies that specify the allowed communication between devices on that network. However, there is a distinction between security policies and the technologies that implement those policies. There is also often a distinction between intended policy and deployed or configured policy. Therefore there is a need to confirm compliance between policy and reality in a network. This is especially true in industrial control systems where there is a lot of network infrastructure and special purpose devices which can not be scanned or analyzed using traditional cybersecurity tools. This work discusses the first steps of a project that automatically detects the security policy as implemented in the control rules of an SDN switch, deployed in an industrial control system network.
更多
查看译文
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要