Keywords :
field-based testing, software-defined networks, security testing, cybersecurity
Abstract :
[en] We present FISTS, a tool that enables security testing of configuration updates in software-defined networks (SDNs). In contrast to conventional approaches, which are model-based and coupled to a specific SDN system, FISTS is entirely black-box thus enabling testing of different platforms, which is necessary for most industries since they typically use proprietary SDN frameworks.
FISTS works by probing the hosts on a network before and after an SDN reconfiguration, automatically identifying corresponding nodes, and determining their port state change; finally, it leverages anomaly detection algorithms to prioritize the inspection of hosts data. FISTS also enable engineers to minimize the number of inspected nodes while maximizing the vulnerabilities found by avoiding the inspection of consecutive false alarms.
We have evaluated FISTS on 220 new and unique datasets based on distinct configuration scenarios; our results show that FISTS leads to best results (up to 0.99 recall) with COF and HBOS, but KNN leads to close recall and minimal execution time. Further, it enables detecting all vulnerable hosts by inspecting less than 10\% of the monitored data.
A demo of FISTS is available online at the following URL: https:// youtu.be/UIMwFqAvAXg. The tool is available (open surce) at: https: //doi.org/10.5281/zenodo.18201382.
Scopus citations®
without self-citations
0