Dynamic security metrics for measuring the effectiveness of moving target defense techniques

被引:19
|
作者
Hong, Jin B. [1 ]
Enoch, Simon Yusuf [2 ]
Kim, Dong Seong [2 ]
Nhlabatsi, Armstrong [3 ]
Fetais, Noora [3 ]
Khan, Khaled M. [3 ]
机构
[1] Univ Western Australia, Dept Comp Sci & Software Engn, Nedlands, WA, Australia
[2] Univ Canterbury, Dept Comp Sci & Software Engn, Christchurch, New Zealand
[3] Qatar Univ, Dept Comp Sci & Engn, KINDI Comp Lab, Doha, Qatar
关键词
Emerging networking technology; Moving target defense; Security analysis; Security metric; Security model; SURVIVABILITY;
D O I
10.1016/j.cose.2018.08.003
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Moving Target Defense (MTD) utilizes granularity, flexibility and elasticity properties of emerging networking technologies in order to continuously change the attack surface. There are many different MTD techniques proposed in the past decade to thwart cyberattacks. Due to the diverse range of different MTD techniques, it is of paramount importance to assess and compare their effectiveness. However, each technique causes distinct (dynamic) changes in the network, making an objective comparison difficult. In this paper, we incorporate MTD techniques into a temporal graph-based graphical security model, and develop a new set of dynamic security metrics to assess and compare their effectiveness. To this end, we first categorize and compare different attack and defense efforts. Second, we describe the temporal graph-based graphical security model to capture dynamic changes made by various MTD techniques in the network. We then develop a new set of security metrics for attack and defense efforts to evaluate the effectiveness of the MTD techniques. We implement two different MTD techniques, namely network topology shuffle and software diversity, and show their effectiveness against a targeted attack scenario in our experimental analysis. The results demonstrate that the proposed dynamic security metrics can capture different properties of MTD techniques, permitting a more fine-grained comparison and offering guidance for selecting the most effective MTD technique. (C) 2018 Elsevier Ltd. All rights reserved.
引用
收藏
页码:33 / 52
页数:20
相关论文
共 50 条
  • [31] On Effectiveness of Detecting FDI Attacks on Power Grid using Moving Target Defense
    Zhang, Zhenyong
    Deng, Ruilong
    Yau, David
    Cheng, Peng
    Chen, Jiming
    2019 IEEE POWER & ENERGY SOCIETY INNOVATIVE SMART GRID TECHNOLOGIES CONFERENCE (ISGT), 2019,
  • [32] A Formal Verification of Configuration-Based Mutation Techniques for Moving Target Defense
    Rahim, Muhammad Abdul Basit Ur
    Al-Shaer, Ehab
    Duan, Qi
    SECURITY AND PRIVACY IN COMMUNICATION NETWORKS (SECURECOMM 2020), PT I, 2020, 335 : 61 - 79
  • [33] Performance-Based Cyber Resilience Metrics: An Applied Demonstration Toward Moving Target Defense
    Hossain-Mckenzie, S.
    Lai, C.
    Chavez, A.
    Vugrin, E.
    IECON 2018 - 44TH ANNUAL CONFERENCE OF THE IEEE INDUSTRIAL ELECTRONICS SOCIETY, 2018, : 766 - 773
  • [34] A Security SLA-Driven Moving Target Defense Framework to Secure Cloud Applications
    Casola, Valentina
    De Benedictis, Alessandra
    Rak, Massimiliano
    Villano, Umberto
    PROCEEDINGS OF THE 5TH ACM WORKSHOP ON MOVING TARGET DEFENSE (MTD'18), 2018, : 48 - 56
  • [35] A Secure Hash Commitment Approach for Moving Target Defense of Security-critical Services
    Mulamba, Dieudonne
    Amarnath, Athith
    Bezawada, Bruhadeshwar
    Ray, Indrajit
    PROCEEDINGS OF THE 5TH ACM WORKSHOP ON MOVING TARGET DEFENSE (MTD'18), 2018, : 59 - 68
  • [36] Distributed Shadow Controllers based Moving Target Defense Framework for Control Plane Security
    Hyder, Muhammad Faraz
    Ismail, Muhammad Ali
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2019, 10 (12) : 150 - 156
  • [37] Moving target defense controller of mobile system based on Openflow sensor security scheme
    Niu, Xin
    Lu, Jiazhong
    COMPUTER COMMUNICATIONS, 2020, 161 (161) : 142 - 149
  • [38] MPBSD: A Moving Target Defense Approach for Base Station Security in Wireless Sensor Networks
    Chin, Tommy
    Xiong, Kaiqi
    WIRELESS ALGORITHMS, SYSTEMS, AND APPLICATIONS, WASA 2016, 2016, 9798 : 487 - 498
  • [39] xG Security: Zero-Trust and Moving Target Defense in Decentralized Learning Environment
    Abdelhay, Zeyad
    Refaey, Ahmed
    20TH INTERNATIONAL WIRELESS COMMUNICATIONS & MOBILE COMPUTING CONFERENCE, IWCMC 2024, 2024, : 1820 - 1825
  • [40] Effectiveness Evaluation of Moving Network Defense Based on Host Security State Transition Model
    Liu J.
    Zhang H.
    Yang Y.
    Wang Y.
    Liu, Jiang (liujiang2333@163.com), 1600, Science Press (39): : 509 - 517