commoncriteria / sdn-controller

Protection Profile for Software Defined Networking Controllers
The Unlicense
3 stars 0 forks source link

ESR, Essential Security Requirements #7

Closed tbrooks06 closed 1 week ago

tbrooks06 commented 2 years ago

Add the following security requirement: The SDN Controller shall provide a moving target defense mechanism (MTD) that protects the network from attacks by using dynamic network configuration.

Rationale: MTD is a use case where SDN can be leveraged in order to provide attack surface obfuscation. Utilizing the programmability and flexibility of a SDN Controller, MTD obfuscates the attack surface including host mutation obfuscation, ports obfuscation, and obfuscation based on decoy servers, thereby enhancing the unpredictability of the networking environment.

njgengo commented 2 years ago

Thank you for your input. Will ask the Edit Team to make the change:

Edit Team, please make the change that was written in the issue above (creditted to tbrooks06). Thanks.

jfisherbah commented 2 years ago

change made 11/29, will be reflected in latest build