Research and development of moving target defense technology

被引:0
|
作者
Cai G. [1 ,2 ]
Wang B. [1 ]
Wang T. [1 ]
Luo Y. [1 ]
Wang X. [1 ]
Cui X. [2 ]
机构
[1] College of Computer, National University of Defense Technology, Changsha
[2] Crop 95942, Wuhan
关键词
Attack surface; Dynamic shifting; Moving target defense; Resiliency; Security;
D O I
10.7544/issn1000-1239.2016.20150225
中图分类号
学科分类号
摘要
Nowadays, network configurations are typically deterministic, static, and homogeneous. These features reduce the difficulties for cyber attackers scanning the network to identify specific targets and gather essential information, which gives the attackers asymmetric advantages of building up, launching and spreading attacks. Thus the defenders are always at a passive position, and the existing defense mechanisms and approaches cannot reverse this situation. Moving target defense (MTD) is proposed as a new revolutionary technology to alter the asymmetric situation of attacks and defenses. It keeps moving the attack surface of the protected target through dynamic shifting, which can be controlled and managed by the administrator. In this way, the attack surface exposed to attackers appears chaotic and changes over time. Therefore, the work effort, i.e., the cost and complexity, for the attackers to launch a successful attack, will be greatly increased. As a result, the probability of successful attacks will be decreased, and the resiliency and security of the protected target will be enhanced effectively. In this paper, we firstly introduce the basic concepts of MTD, and classify the related works into categories according to their research field. Then, under each category, we give a detailed description on the existing work, and analyze and summarize them separately. Finally, we present our understandings on MTD, and summarize the current research status, and further discuss the development trends in this field. © 2016, Science Press. All right reserved.
引用
收藏
页码:968 / 987
页数:19
相关论文
共 99 条
  • [91] Han Y., Lu W., Xu S., Characterizing the power of moving target defense via cyber epidemic dynamics, Proc of the 2014 Symp and Bootcamp on the Science of Security, pp. 10-11, (2014)
  • [92] Zhuang R., Deloach S.A., Ou X., A model for analyzing the effect of moving target defenses on enterprise networks, Proc of the 9th Annual Cyber and Information Security Research Conf, pp. 73-76, (2014)
  • [93] Carroll T.E., Crouse M., Fulp E.W., Et al., Analysis of network address shuffling as a moving target defense, Proc of 2014 IEEE Int Conf on Communications (ICC), pp. 701-706, (2014)
  • [94] Luo Y., Wang B., Cai G., Effectiveness of port hopping as a moving target defense, Proc of the 7th Int Conf on Security Technology (SecTech), pp. 7-10, (2014)
  • [95] Xu J., Guo P., Zhao M., Et al., Comparing different moving target defense techniques, Proc of the 1st ACM Workshop on Moving Target Defense, pp. 97-107, (2014)
  • [96] Okhravi H., Riordan J., Carter K., Quantitative evaluation of dynamic platform techniques as a defensive mechanism, Research in Attacks, Intrusions and Defenses, pp. 405-425, (2014)
  • [97] Okhravi H., Comella A., Robinson E., Et al., Creating a cyber moving target for critical infrastructure applications, Critical Infrastructure Protection V, pp. 107-123, (2011)
  • [98] Murphy M., Larsen P., Brunthaler S., Et al., Software profiling options and their effects on security based diversification, Proc of the 1st ACM Workshop on Moving Target Defense, pp. 87-96, (2014)
  • [99] Zhu M., Hu Z., Liu P., Reinforcement learning algorithms for adaptive cyber defense against Heartbleed, Proc of the 1st ACM Workshop on Moving Target Defense, pp. 51-59, (2014)