Analysis of Network Address Shuffling as a Moving Target Defense

被引:0
|
作者
Carroll, Thomas E. [1 ]
Crouse, Michael [2 ]
Fulp, Errin W. [3 ,4 ]
Berenhaut, Kenneth S. [3 ,4 ]
机构
[1] Pacific NW Natl Lab, Richland, WA 99352 USA
[2] Harvard Univ, Dept Comp Sci, Cambridge, MA 02138 USA
[3] Wake Forest Univ, Dept Comp Sci, Winston Salem, NC 27109 USA
[4] Wake Forest Univ, Dept Math, Winston Salem, NC 27109 USA
关键词
D O I
暂无
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
Address shuffling is a type of moving target defense that prevents an attacker from reliably contacting a system by periodically remapping network addresses. Although limited testing has demonstrated it to be effective, little research has been conducted to examine the theoretical limits of address shuffling. As a result, it is difficult to understand how effective shuffling is and under what circumstances it is a viable moving target defense. This paper introduces probabilistic models that can provide insight into the performance of address shuffling. These models quantify the probability of attacker success in terms of network size, quantity of addresses scanned, quantity of vulnerable systems, and the frequency of shuffling. Theoretical analysis shows that shuffling is an acceptable defense if there is a small population of vulnerable systems within a large network address space, however shuffling has a cost for legitimate users. These results will also be shown empirically using simulation and actual traffic traces.
引用
收藏
页码:701 / 706
页数:6
相关论文
共 50 条
  • [41] RPAH: A Moving Target Network Defense Mechanism Naturally Resists Reconnaissances and Attacks
    Luo, Yue-Bin
    Wang, Bao-Sheng
    Wang, Xiao-Feng
    Zhang, Bo-Feng
    Hu, Wei
    IEICE TRANSACTIONS ON INFORMATION AND SYSTEMS, 2017, E100D (03): : 496 - 510
  • [42] Moving Target Defense Router: MaTaDoR
    Ufuk, Berkan
    Sandikkaya, Mehmet Tahir
    SECRYPT : PROCEEDINGS OF THE 19TH INTERNATIONAL CONFERENCE ON SECURITY AND CRYPTOGRAPHY, 2022, : 649 - 654
  • [44] A Framework for Moving Target Defense Quantification
    Connell, Warren
    Albanese, Massimiliano
    Venkatesan, Sridhar
    ICT SYSTEMS SECURITY AND PRIVACY PROTECTION, SEC 2017, 2017, 502 : 124 - 138
  • [45] Moving Target Defense for the CloudControl Game
    Hamasaki, Koji
    Hohjo, Hitoshi
    ADVANCES IN INFORMATION AND COMPUTER SECURITY, IWSEC 2021, 2021, 12835 : 241 - 251
  • [46] A moving target DDoS defense mechanism
    Wang, Huangxin
    Jia, Quan
    Fleck, Dan
    Powell, Walter
    Li, Fei
    Stavrou, Angelos
    COMPUTER COMMUNICATIONS, 2014, 46 : 10 - 21
  • [47] Moving Target Defense Techniques: A Survey
    Lei, Cheng
    Zhang, Hong-Qi
    Tan, Jing-Lei
    Zhang, Yu-Chen
    Liu, Xiao-Hu
    SECURITY AND COMMUNICATION NETWORKS, 2018,
  • [48] A comparison of moving target defense strategies
    Zhang, Jingzhe
    Wang, Dongxia
    Feng, Xuewei
    2018 IEEE 15TH INTERNATIONAL CONFERENCE ON MOBILE AD HOC AND SENSOR SYSTEMS (MASS), 2018, : 543 - 547
  • [49] Moving Target Defense for Avionic Systems
    Heydari, Vahid
    2018 NATIONAL CYBER SUMMIT: RESEARCH TRACK (NCS 2018), 2018, : 53 - 57
  • [50] ChameleonSoft: A Moving Target Defense System
    Azab, Mohamed
    Hassan, Riham
    Eltoweissy, Mohamed
    PROCEEDINGS OF THE 7TH INTERNATIONAL CONFERENCE ON COLLABORATIVE COMPUTING: NETWORKING, APPLICATIONS AND WORKSHARING (COLLABORATECOM), 2011, : 241 - 250