Skip to content

Network Segmentation: Addresses Multiple intents #85

@nandhued

Description

@nandhued

Generate zero-trust policies generated by the discovery engine based on application behaviour

The attacks that can be mitigated are:

  • Exploit public-facing applications
  • Registration of malicious network functions
  • Software Deployment Tools
  • Malicious VNF installation

Techniques:

  1. Radio control manipulation via rogue xApps
  2. Trusted Relationship
  3. Registration of malicious network functions
  4. Software Deployment Tools
  5. gNodeB Component Manipulation
  6. Network Sniffing [Tactic: Credential Access]
  7. Adversary-in-the-Middle [Tactic: Credential Access]
  8. Network Sniffing [Tactic: Resource Development]
  9. Adversary-in-the-Middle [Tactic: Resource Development]

Parameters need to be provided such which container is to be isolated

The adapters that are involved are:

KubeArmor, Network Policy, Service Mesh

Design doc

Metadata

Metadata

Labels

IntentIntents configure/driver adaptersengineAdapters configure the security enginestactic: initialAccess

Type

No type

Projects

Status

❌ Blocked

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions