The International Arab Journal of Information Technology (IAJIT)


On Detection and Prevention of Zero-Day Attack

Networks attacker may identify the network vulnerability within less than one day; this kind of attack is known as zero-day attack. This undiscovered vulnerability by vendors empowers the attacker to affect or damage the network operation, because vendors have less than one day to fix this new exposed vulnerability. The existing defense mechanisms against the zero-day attacks focus on the prevention effort, in which unknown or new vulnerabilities typically cannot be detected. To the best of our knowledge the protection mechanism against zero-day attack is not widely investigated for Software-Defined Networks (SDNs). Thus, in this work we are motivated to develop a new zero-day attack detection and prevention mechanism for SDNs by modifying Cuckoo sandbox tool. The mechanism is implemented and tested under UNIX system. The experiments results show that our proposed mechanism successfully stops the zero-day malwares by isolating the infected clients, in order to prevent the malwares from spreading to other clients. Moreover, results show the effectiveness of our mechanism in terms of detection accuracy and response time.

[24] Wang L., Zhang M., Jajodia S., Singhal A., and Albanese M., “Modeling Network Diversity for Evaluating The Robustness of Networks Against Zero-Day Attacks,” in Proceedings of the 19th European Symposium on Research in Computer Security, Wroclaw, pp. 494-511, 2014. 670 The International Arab Journal of Information Technology, Vol. 17, No. 4A, Special Issue 2020 Huthifh Al-Rushdan received his B.Sc. degree in Computer Engineering, Jordan University of Science and Technology, Jordan, 2007. He received his M.Sc. in Computer Engineering, Jordan University of Science and Technology, 2018. Currenly, he is head of datacenters in Jordan Army. His research interests are in SDN, compuer security, datacenters, computer networks and virtualization. Mohammad Shurman received his B.Sc. degree in Electrical and Computer Engineering from Jordan University of Science and Technology, Irbid, Jordan, 2000. Also, he received his M.Sc. and Ph.D. degrees in Computer Engineering-Wireless Networks from University of Alabama-Huntsville (UAH) in 2003 and 2006, respectively. Presently, he is with the Network Engineering and Security Department, Jordan University of Science and Technology, Irbid, Jordan. His research interests include wireless Ad-hoc networks, security and key management of wireless networks, wireless sensor networks, network coding, wireless communication and mobile networks, software defined networks (SDN), cognitive radio, WiMAX, 4G and 5G technologies and Blockchains. Sharhabeel Alnabelsi is an associate professor at Computer Engineering Dept. at Al-Balqa Applied University, Amman, Jordan. Also, he is an associate professor in Computer Engineering Dept. at Al Ain University, UAE. He received his Ph.D. in Computer Engineering from Iowa State University, USA, 2012. Also, he received his M.Sc. in Computer Engineering from The University of Alabama in Huntsville, USA, 2007. His research interests are cognitive radio networks, wireless sensors networks, network resources optimization, and cloud computing. He is a member of honorary societies including Eta Kappa Nu and Phi Kappa Phi.