Dynamic security metrics for measuring the effectiveness of moving target defense techniques

被引:19
|
作者
Hong, Jin B. [1 ]
Enoch, Simon Yusuf [2 ]
Kim, Dong Seong [2 ]
Nhlabatsi, Armstrong [3 ]
Fetais, Noora [3 ]
Khan, Khaled M. [3 ]
机构
[1] Univ Western Australia, Dept Comp Sci & Software Engn, Nedlands, WA, Australia
[2] Univ Canterbury, Dept Comp Sci & Software Engn, Christchurch, New Zealand
[3] Qatar Univ, Dept Comp Sci & Engn, KINDI Comp Lab, Doha, Qatar
关键词
Emerging networking technology; Moving target defense; Security analysis; Security metric; Security model; SURVIVABILITY;
D O I
10.1016/j.cose.2018.08.003
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Moving Target Defense (MTD) utilizes granularity, flexibility and elasticity properties of emerging networking technologies in order to continuously change the attack surface. There are many different MTD techniques proposed in the past decade to thwart cyberattacks. Due to the diverse range of different MTD techniques, it is of paramount importance to assess and compare their effectiveness. However, each technique causes distinct (dynamic) changes in the network, making an objective comparison difficult. In this paper, we incorporate MTD techniques into a temporal graph-based graphical security model, and develop a new set of dynamic security metrics to assess and compare their effectiveness. To this end, we first categorize and compare different attack and defense efforts. Second, we describe the temporal graph-based graphical security model to capture dynamic changes made by various MTD techniques in the network. We then develop a new set of security metrics for attack and defense efforts to evaluate the effectiveness of the MTD techniques. We implement two different MTD techniques, namely network topology shuffle and software diversity, and show their effectiveness against a targeted attack scenario in our experimental analysis. The results demonstrate that the proposed dynamic security metrics can capture different properties of MTD techniques, permitting a more fine-grained comparison and offering guidance for selecting the most effective MTD technique. (C) 2018 Elsevier Ltd. All rights reserved.
引用
收藏
页码:33 / 52
页数:20
相关论文
共 50 条
  • [41] SOCMTD: Selecting Optimal Countermeasure for Moving Target Defense Using Dynamic Game
    Hu, Hao
    Liu, Jing
    Tan, Jinglei
    Liu, Jiang
    KSII TRANSACTIONS ON INTERNET AND INFORMATION SYSTEMS, 2020, 14 (10): : 4157 - 4175
  • [42] A Network Coding and DES Based Dynamic Encryption Scheme for Moving Target Defense
    Tang, Hanqi
    Sun, Qifu Tyler
    Yang, Xiaolong
    Long, Keping
    IEEE ACCESS, 2018, 6 : 26059 - 26068
  • [43] Survey on Attack Surface Dynamic Transfer Technology Based on Moving Target Defense
    Zhou Y.-Y.
    Cheng G.
    Guo C.-S.
    Dai M.
    Ruan Jian Xue Bao/Journal of Software, 2018, 29 (09): : 2799 - 2820
  • [44] Information security: The moving target
    Dlamini, M. T.
    Eloff, J. H. P.
    Eloff, M. M.
    COMPUTERS & SECURITY, 2009, 28 (3-4) : 189 - 198
  • [45] Moving Target Network Defense Effectiveness Evaluation Based on Change-Point Detection
    Lei, Cheng
    Ma, Duo-he
    Zhang, Hong-qi
    Wang, Li-ming
    MATHEMATICAL PROBLEMS IN ENGINEERING, 2016, 2016
  • [46] Moving Target Defense Router: MaTaDoR
    Ufuk, Berkan
    Sandikkaya, Mehmet Tahir
    SECRYPT : PROCEEDINGS OF THE 19TH INTERNATIONAL CONFERENCE ON SECURITY AND CRYPTOGRAPHY, 2022, : 649 - 654
  • [48] A Framework for Moving Target Defense Quantification
    Connell, Warren
    Albanese, Massimiliano
    Venkatesan, Sridhar
    ICT SYSTEMS SECURITY AND PRIVACY PROTECTION, SEC 2017, 2017, 502 : 124 - 138
  • [49] Overview on Moving Target Network Defense
    Zhou, Xuan
    Lu, Yuliang
    Wang, Yongjie
    Yan, Xuehu
    2018 IEEE 3RD INTERNATIONAL CONFERENCE ON IMAGE, VISION AND COMPUTING (ICIVC), 2018, : 821 - 827
  • [50] Moving Target Defense for the CloudControl Game
    Hamasaki, Koji
    Hohjo, Hitoshi
    ADVANCES IN INFORMATION AND COMPUTER SECURITY, IWSEC 2021, 2021, 12835 : 241 - 251