DocumentCode
3488455
Title
A dynamic model building process for virtual network security assessment
Author
Goyette, R. ; Karmouch, A.
Author_Institution
Fac. of Eng., Univ. of Ottawa, Ottawa, ON, Canada
fYear
2011
fDate
23-26 Aug. 2011
Firstpage
482
Lastpage
487
Abstract
Network virtualization - in which network topologies and protocols are tailor-made for individual service providers across multiple infrastructure providers - is a concept that holds great promise for the future internet. However, security in the Virtual Network (VNet) context is difficult to assess and understand because service providers have no visibility into the infrastructure over which their networks operate which could be a significant concern from an adoption perspective. In a previous work, we introduced a VNet Security Assessment Process to address this challenge by building a security preference model based on the input of a group of security experts. However, a flexibility-limiting factor of the process is the requirement for security experts to meet each time a model change is required. In this paper, we introduce DS-MACBETH which combines Dempster-Shafer theory (DST) with the multi-criteria decision making process MACBETH (Measuring Attractiveness by a Categorical Based Evaluation Technique). We combine DST with MACBETH in order to allow security experts to contribute to model building in an asynchronous, distributed fashion. We integrate DS-MACBETH into our previous VNet security assessment process to achieve a dynamic security model building process whose sources of knowledge can be expanded beyond human sources of security knowledge (e.g. sensors, expert systems, etc).
Keywords
Internet; decision making; inference mechanisms; protocols; telecommunication network topology; telecommunication security; uncertainty handling; DS-MACBETH; Dempster-Shafer theory; Internet; VNet security assessment; building process; categorical based evaluation technique; dynamic security model; human sources; measuring attractiveness; multicriteria decision making process; multiple infrastructure providers; network protocols; network topologies; network virtualization; security preference; service providers; virtual network security assessment; Buildings; Context; Decision making; Engineering profession; Marine vehicles; Protocols; Security; Dempster-Shafer; MACBETH; security; virtual network;
fLanguage
English
Publisher
ieee
Conference_Titel
Communications, Computers and Signal Processing (PacRim), 2011 IEEE Pacific Rim Conference on
Conference_Location
Victoria, BC
ISSN
1555-5798
Print_ISBN
978-1-4577-0252-5
Electronic_ISBN
1555-5798
Type
conf
DOI
10.1109/PACRIM.2011.6032941
Filename
6032941
Link To Document