Analysis of Network Address Shuffling as a Moving Target Defense

被引:0
|
作者
Carroll, Thomas E. [1 ]
Crouse, Michael [2 ]
Fulp, Errin W. [3 ,4 ]
Berenhaut, Kenneth S. [3 ,4 ]
机构
[1] Pacific NW Natl Lab, Richland, WA 99352 USA
[2] Harvard Univ, Dept Comp Sci, Cambridge, MA 02138 USA
[3] Wake Forest Univ, Dept Comp Sci, Winston Salem, NC 27109 USA
[4] Wake Forest Univ, Dept Math, Winston Salem, NC 27109 USA
关键词
D O I
暂无
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
Address shuffling is a type of moving target defense that prevents an attacker from reliably contacting a system by periodically remapping network addresses. Although limited testing has demonstrated it to be effective, little research has been conducted to examine the theoretical limits of address shuffling. As a result, it is difficult to understand how effective shuffling is and under what circumstances it is a viable moving target defense. This paper introduces probabilistic models that can provide insight into the performance of address shuffling. These models quantify the probability of attacker success in terms of network size, quantity of addresses scanned, quantity of vulnerable systems, and the frequency of shuffling. Theoretical analysis shows that shuffling is an acceptable defense if there is a small population of vulnerable systems within a large network address space, however shuffling has a cost for legitimate users. These results will also be shown empirically using simulation and actual traffic traces.
引用
收藏
页码:701 / 706
页数:6
相关论文
共 50 条
  • [31] Moving Target Defense Against Network Reconnaissance with Software Defined Networking
    Wang, Li
    Wu, Dinghao
    INFORMATION SECURITY, (ISC 2016), 2016, 9866 : 203 - 217
  • [32] A Brief review on Network Identity-based Moving Target Defense
    Saputro, Nico
    2023 INTERNATIONAL CONFERENCE ON INFORMATION NETWORKING, ICOIN, 2023, : 610 - 615
  • [33] Thwart Eavesdropping Attacks on Network Communication Based on Moving Target Defense
    Ma, Duohe
    Wang, Liming
    Lei, Cheng
    Xu, Zhen
    Zhang, Hongqi
    Li, Meng
    2016 IEEE 35TH INTERNATIONAL PERFORMANCE COMPUTING AND COMMUNICATIONS CONFERENCE (IPCCC), 2016,
  • [34] SDN-based solutions for Moving Target Defense network protection
    Kampanakis, Panos
    Perros, Harry
    Beyene, Tsegereda
    2014 IEEE 15TH INTERNATIONAL SYMPOSIUM ON A WORLD OF WIRELESS, MOBILE AND MULTIMEDIA NETWORKS (WOWMOM), 2014,
  • [35] Empirical Assessment of Network-based Moving Target Defense Approaches
    Van Leeuwen, Brian P.
    Stout, William M. S.
    Urias, Vincent E.
    MILCOM 2016 - 2016 IEEE MILITARY COMMUNICATIONS CONFERENCE, 2016, : 764 - 769
  • [36] Strengthening Network-Based Moving Target Defense with Disposable Identifiers
    Park, Taekeun
    Kim, Keewon
    IEICE TRANSACTIONS ON INFORMATION AND SYSTEMS, 2022, E105D (10) : 1799 - 1802
  • [37] Optimizing a Network Layer Moving Target Defense for Specific System Architectures
    Hardman, Owen
    Groat, Stephen
    Marchany, Randy
    Tront, Joseph
    2013 ACM/IEEE SYMPOSIUM ON ARCHITECTURES FOR NETWORKING AND COMMUNICATIONS SYSTEMS (ANCS), 2013, : 117 - 118
  • [38] Network moving target defense technique based on optimal forwarding path migration
    Lei C.
    Ma D.-H.
    Zhang H.-Q.
    Han Q.
    Yang Y.-J.
    Ma, Duo-He (maduohe@iie.ac.cn), 2017, Editorial Board of Journal on Communications (38): : 133 - 143
  • [39] An SDN-Based Moving Target Defense as a Countermeasure to Prevent Network Scans
    Chiba, Shoya
    Guillen, Luis
    Izumi, Satoru
    Abe, Toru
    Suganuma, Takuo
    IEICE TRANSACTIONS ON COMMUNICATIONS, 2022, E105B (11) : 1400 - 1407
  • [40] A Network Coding and DES Based Dynamic Encryption Scheme for Moving Target Defense
    Tang, Hanqi
    Sun, Qifu Tyler
    Yang, Xiaolong
    Long, Keping
    IEEE ACCESS, 2018, 6 : 26059 - 26068