<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "JATS-journalpublishing1-3.dtd">
<article article-type="research-article" dtd-version="1.3" xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xml:lang="ru"><front><journal-meta><journal-id journal-id-type="publisher-id">mais</journal-id><journal-title-group><journal-title xml:lang="ru">Моделирование и анализ информационных систем</journal-title><trans-title-group xml:lang="en"><trans-title>Modeling and Analysis of Information Systems</trans-title></trans-title-group></journal-title-group><issn pub-type="ppub">1818-1015</issn><issn pub-type="epub">2313-5417</issn><publisher><publisher-name>Yaroslavl State University</publisher-name></publisher></journal-meta><article-meta><article-id pub-id-type="doi">10.18255/1818-1015-2019-1-134-145</article-id><article-id custom-type="elpub" pub-id-type="custom">mais-1168</article-id><article-categories><subj-group subj-group-type="heading"><subject>Research Article</subject></subj-group><subj-group subj-group-type="section-heading" xml:lang="ru"><subject>Computer System Organization</subject></subj-group></article-categories><title-group><article-title>«Общие критерии» и безопасность программно-конфигурируемых сетей</article-title><trans-title-group xml:lang="en"><trans-title>”Common Criteria” and Software Defined Network Security</trans-title></trans-title-group></title-group><contrib-group><contrib contrib-type="author" corresp="yes"><contrib-id contrib-id-type="orcid">https://orcid.org/0000-0002-1427-2440</contrib-id><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Петухов</surname><given-names>Андрей Николаевич</given-names></name><name name-style="western" xml:lang="en"><surname>Petukhov</surname><given-names>Andrey N.</given-names></name></name-alternatives><bio xml:lang="ru"><p>канд. техн. наук</p><p>пл. Шокина, 1, г. Зеленоград, г. Москва, 124498</p></bio><bio xml:lang="en"><p>PhD</p><p>Bld. 1, Shokin Square, Zelenograd, Moscow</p></bio><email xlink:type="simple">anpetukhov@yandex.ru</email><xref ref-type="aff" rid="aff-1"/></contrib><contrib contrib-type="author" corresp="yes"><contrib-id contrib-id-type="orcid">https://orcid.org/0000-0003-0011-7180</contrib-id><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Пилюгин</surname><given-names>Павел Львович</given-names></name><name name-style="western" xml:lang="en"><surname>Pilyugin</surname><given-names>Paul L.</given-names></name></name-alternatives><bio xml:lang="ru"><p>канд.техн. наук</p><p>Ленинские горы, 1, г. Москва, 119991</p></bio><bio xml:lang="en"><p>PhD</p><p>GSP-1, Leninskie Gory, Moscow, 119991</p></bio><email xlink:type="simple">ppl@mail.ru</email><xref ref-type="aff" rid="aff-2"/></contrib></contrib-group><aff-alternatives id="aff-1"><aff xml:lang="ru"><institution>Национальный исследовательский университет «МИЭТ»</institution><country>Россия</country></aff><aff xml:lang="en"><institution>National Research University of Electronic Technology – MIET</institution><country>Russian Federation</country></aff></aff-alternatives><aff-alternatives id="aff-2"><aff xml:lang="ru"><institution>Московский государственный университет имени М.В. Ломоносова</institution><country>Россия</country></aff><aff xml:lang="en"><institution>Lomonosov Moscow State University</institution><country>Russian Federation</country></aff></aff-alternatives><pub-date pub-type="collection"><year>2019</year></pub-date><pub-date pub-type="epub"><day>15</day><month>03</month><year>2019</year></pub-date><volume>26</volume><issue>1</issue><fpage>134</fpage><lpage>145</lpage><permissions><copyright-statement>Copyright &amp;#x00A9; Петухов А.Н., Пилюгин П.Л., 2019</copyright-statement><copyright-year>2019</copyright-year><copyright-holder xml:lang="ru">Петухов А.Н., Пилюгин П.Л.</copyright-holder><copyright-holder xml:lang="en">Petukhov A.N., Pilyugin P.L.</copyright-holder><license xml:lang="ru" license-type="creative-commons-attribution" xlink:href="https://creativecommons.org/licenses/by/4.0/" xlink:type="simple"><license-p>Данная работа распространяется под лицензией Creative Commons Attribution 4.0.</license-p></license><license xml:lang="en" license-type="creative-commons-attribution" xlink:href="https://creativecommons.org/licenses/by/4.0/" xlink:type="simple"><license-p>This work is licensed under a Creative Commons Attribution 4.0 License.</license-p></license></permissions><self-uri xlink:href="https://www.mais-journal.ru/jour/article/view/1168">https://www.mais-journal.ru/jour/article/view/1168</self-uri><abstract><p>«Общие критерии» (ISO 15408) – общепризнанный и широко применимый подход к управлению и оценке решений в области информационной безопасности. «Общие критерии» опираются на разработку общей концептуальной основы для ключевых решений безопасности, включая профили защиты и целевые объекты безопасности. Концептуальная основа разработки подразумевает определение следующих элементов: цели и предположения безопасности (для среды и объекта), угрозы и политики безопасности, а также функциональные требования и требования к обеспечению безопасности. Специфика решений по обеспечению безопасности SDN во многом обусловлена фундаментальными архитектурными принципами самой технологии SDN – в первую очередь разделением потоков управления и данных, а также условиями применения протокола OpenFlow. Тем не менее, проактивные (угрозы и политики), пассивные (цели и предположения) и реактивные (требования) аспекты управления безопасностью остаются весьма актуальными для такого типа решений безопасности. В статье рассматриваются особенности применения единых критериев оценки безопасности SDN и практического опыта Московского технического университета связи и информатики при разработке профиля защиты. Новый класс сетевых атак на коммутаторы и контроллеры SDN может использовать как данные, так и компоненты управления. В дополнение к традиционным уязвимостям централизация функций управления открывает путь для новых угроз безопасности путем изоляции деятельности контроллера и обмена управляющими сообщениями. Поэтому выявление и анализ угроз, политик и требований, специфичных для безопасности модуля управления SDN, становится новым приоритетом.</p></abstract><trans-abstract xml:lang="en"><p>«Common criteria» (ISO 15408) is a universally recognized and broadly applicable approach to information security solutions management and evaluation. «Common criteria» leans on developing a shared conceptual basis for key security solution modules including protection profiles and security targets. Conceptual basis development implies defining the following elements: security objectives and assumptions (for the environment and the object), threats and security policies, as well as functional and assurance requirements. The specifics of SDN (software defined network) security solutions is largely driven by fundamental architectural principles of SDN technology itself − primarily by the separation of control and data flows, − and by conditions imposed by Open Flow protocol application. However, proactive (threats and policies), passive (objectives and assumptions) and reactive (requirements) aspects of security management remain highly relevant for this type of security solutions. This paper discusses the Common Criteria application specifics for assessing the SDN security and practical MTUCI (Moscow Technical University of Communications and Informatics) experience in the development of the protection profile. A new class of network attacks on SDN switches and controllers can involve either data or control components. In addition to traditional vulnerabilities, centralization of management functions paves way for new security threats by isolating controller activity and administrative message exchange. Therefore, identifying and analyzing threats, policies and requirements specific to SDN control module security becomes an emerging priority.</p></trans-abstract><kwd-group xml:lang="ru"><kwd>безопасность программно-конфигурируемых сетей</kwd><kwd>общие критерии</kwd><kwd>профиль защиты</kwd></kwd-group><kwd-group xml:lang="en"><kwd>security of software defined networks</kwd><kwd>general criteria</kwd><kwd>security profile</kwd></kwd-group><funding-group><funding-statement xml:lang="ru">Работа выполнена при поддержке ректората Московского технического университета связи и информатики (МТУСИ): С. Д. Ерохина, Ю. Л. Леохина и А. Ю. Муханова — и при финансировании МТУСИ по направлению «Безопасность критических информационных инфраструктур».</funding-statement><funding-statement xml:lang="en">The work was supported by MTUCI (Moscow Technical University of Communications and Informatics) rectorate: Erokhin S., Leokhin Yu. and Mukhanov A., and with funding from the MTUCI, in the direction of «Security of critical information infrastructures».</funding-statement></funding-group></article-meta></front><back><ref-list><title>References</title><ref id="cit1"><label>1</label><citation-alternatives><mixed-citation xml:lang="ru">ISO/IEC 15408-1:2005 Information technology - Security techniques - Evaluation criteria for IT security - Part 1: Introduction and general model, https://www.iso.org/standard/40612.html.</mixed-citation><mixed-citation xml:lang="en">ISO/IEC 15408-1:2005 Information technology - Security techniques - Evaluation criteria for IT security - Part 1: Introduction and general model, https://www.iso.org/standard/40612.html.</mixed-citation></citation-alternatives></ref><ref id="cit2"><label>2</label><citation-alternatives><mixed-citation xml:lang="ru">Anwer B., et al., "A Slick Control Plane for Network Middleboxes", Open Networking Summit, 2013, http://nextstep-esolutions.com/Clients/ONS2.0/pdf/2013/researchtrack/posterpapers/final/ons2013-final51.pdf.</mixed-citation><mixed-citation xml:lang="en">Anwer B., et al., "A Slick Control Plane for Network Middleboxes", Open Networking Summit, 2013, http://nextstep-esolutions.com/Clients/ONS2.0/pdf/2013/researchtrack/posterpapers/final/ons2013-final51.pdf.</mixed-citation></citation-alternatives></ref><ref id="cit3"><label>3</label><citation-alternatives><mixed-citation xml:lang="ru">Fayazbakhsh S., et al., "FlowTags: Enforcing Network-Wide Policies in the Presence of Dynamic Middlebox Actions", HotSDN'13, ACM, 2013, http://www.cs.columbia.edu/~lierranli/coms6998-8SDNFall2013/papers/Flowtags-HotSDN2013.pdf.</mixed-citation><mixed-citation xml:lang="en">Fayazbakhsh S., et al., "FlowTags: Enforcing Network-Wide Policies in the Presence of Dynamic Middlebox Actions", HotSDN'13, ACM, 2013, http://www.cs.columbia.edu/~lierranli/coms6998-8SDNFall2013/papers/Flowtags-HotSDN2013.pdf.</mixed-citation></citation-alternatives></ref><ref id="cit4"><label>4</label><citation-alternatives><mixed-citation xml:lang="ru">Qazi Z.A., et al., "SIMPLE-fying Middlebox Policy Enforcement Using SDN", SIGCOMM, ACM, 2013.</mixed-citation><mixed-citation xml:lang="en">Qazi Z.A., et al., "SIMPLE-fying Middlebox Policy Enforcement Using SDN", SIGCOMM, ACM, 2013.</mixed-citation></citation-alternatives></ref><ref id="cit5"><label>5</label><citation-alternatives><mixed-citation xml:lang="ru">ONF Threat Analysis for the SDN Architecture. Version 1.0, TR-530, July 2016, https://www.opennetworking.org/wp-content/Threat_Analysis_for_the_SDN_Architecture.pdf.</mixed-citation><mixed-citation xml:lang="en">ONF Threat Analysis for the SDN Architecture. Version 1.0, TR-530, July 2016, https://www.opennetworking.org/wp-content/Threat_Analysis_for_the_SDN_Architecture.pdf.</mixed-citation></citation-alternatives></ref><ref id="cit6"><label>6</label><citation-alternatives><mixed-citation xml:lang="ru">Pilyugin P., Smeliansky R., "Modern security issues in SDN", 2-nd International Conference on Information Technologies, Systems and Networks. ITSN-2017 (Chisinau, Republic of Moldova, 17 - 18 October 2017).</mixed-citation><mixed-citation xml:lang="en">Pilyugin P., Smeliansky R., "Modern security issues in SDN", 2-nd International Conference on Information Technologies, Systems and Networks. ITSN-2017 (Chisinau, Republic of Moldova, 17 - 18 October 2017).</mixed-citation></citation-alternatives></ref><ref id="cit7"><label>7</label><citation-alternatives><mixed-citation xml:lang="ru">ONF Security Foundation Requirements for SDN Controllers. Version 1.0, TR-529, July 2016, https://www.opennetworking.org/wp-content/Security_Foundation_Requirements_for_SDN_Controllers.pdf.</mixed-citation><mixed-citation xml:lang="en">ONF Security Foundation Requirements for SDN Controllers. Version 1.0, TR-529, July 2016, https://www.opennetworking.org/wp-content/Security_Foundation_Requirements_for_SDN_Controllers.pdf.</mixed-citation></citation-alternatives></ref></ref-list><fn-group><fn fn-type="conflict"><p>The authors declare that there are no conflicts of interest present.</p></fn></fn-group></back></article>
