Moving Target Defense for Securing SCADA Communications

被引:15
|
作者
Heydari, Vahid [1 ]
机构
[1] Rowan Univ, Comp Sci Dept, Glassboro, NJ 08028 USA
来源
IEEE ACCESS | 2018年 / 6卷
关键词
SCADA; mobile IPv6; moving target defense; dynamic IP; ATTACKS;
D O I
10.1109/ACCESS.2018.2844542
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In this paper, we introduce a framework for building a secure and private peer to peer communication used in supervisory control and data acquisition networks with a novel Mobile IPv6-based moving target defense strategy. Our approach aids in combating remote cyber-attacks against peer hosts by thwarting any potential attacks at their reconnaissance stage. The IP address of each host is randomly changed at a certain interval creating a moving target to make it difficult for an attacker to find the host. At the same time, the peer host is updated through the use of the binding update procedure (standard Mobile IPv6 protocol). Compared with existing results that can incur significant packet-loss during address rotations, the proposed solution is loss-less. Improving privacy and anonymity for communicating hosts by removing permanent IP addresses from all packets is also one of the major contributions of this paper. Another contribution is preventing black hole attacks and bandwidth depletion DDoS attacks through the use of extra paths between the peer hosts. Recovering the communication after rebooting a host is also a new contribution of this paper. Lab-based simulation results are presented to demonstrate the performance of the method in action, including its overheads. The testbed experiments show zero packet-loss rate during handoff delay.
引用
收藏
页码:33329 / 33343
页数:15
相关论文
共 50 条
  • [21] Overview on Moving Target Network Defense
    Zhou, Xuan
    Lu, Yuliang
    Wang, Yongjie
    Yan, Xuehu
    2018 IEEE 3RD INTERNATIONAL CONFERENCE ON IMAGE, VISION AND COMPUTING (ICIVC), 2018, : 821 - 827
  • [22] Moving Target Defense for the CloudControl Game
    Hamasaki, Koji
    Hohjo, Hitoshi
    ADVANCES IN INFORMATION AND COMPUTER SECURITY, IWSEC 2021, 2021, 12835 : 241 - 251
  • [23] A moving target DDoS defense mechanism
    Wang, Huangxin
    Jia, Quan
    Fleck, Dan
    Powell, Walter
    Li, Fei
    Stavrou, Angelos
    COMPUTER COMMUNICATIONS, 2014, 46 : 10 - 21
  • [24] Moving Target Defense Techniques: A Survey
    Lei, Cheng
    Zhang, Hong-Qi
    Tan, Jing-Lei
    Zhang, Yu-Chen
    Liu, Xiao-Hu
    SECURITY AND COMMUNICATION NETWORKS, 2018,
  • [25] A comparison of moving target defense strategies
    Zhang, Jingzhe
    Wang, Dongxia
    Feng, Xuewei
    2018 IEEE 15TH INTERNATIONAL CONFERENCE ON MOBILE AD HOC AND SENSOR SYSTEMS (MASS), 2018, : 543 - 547
  • [26] Moving Target Defense for Avionic Systems
    Heydari, Vahid
    2018 NATIONAL CYBER SUMMIT: RESEARCH TRACK (NCS 2018), 2018, : 53 - 57
  • [27] A Formal Analysis of Moving Target Defense
    Rahim, Muhammad Abdul Basit Ur
    Duan, Qi
    Al-Shaer, Ehab
    2020 IEEE 44TH ANNUAL COMPUTERS, SOFTWARE, AND APPLICATIONS CONFERENCE (COMPSAC 2020), 2020, : 1802 - 1807
  • [28] ChameleonSoft: A Moving Target Defense System
    Azab, Mohamed
    Hassan, Riham
    Eltoweissy, Mohamed
    PROCEEDINGS OF THE 7TH INTERNATIONAL CONFERENCE ON COLLABORATIVE COMPUTING: NETWORKING, APPLICATIONS AND WORKSHARING (COLLABORATECOM), 2011, : 241 - 250
  • [29] Moving Target Defense for Space Systems
    Jenkins, Chris
    Vugrin, Eric
    Manickam, Indu
    Troutman, Nicholas
    Hazelbaker, Jacob
    Krakowiak, Sarah
    Maxwell, Josh
    Brown, Richard
    2021 IEEE SPACE COMPUTING CONFERENCE (SCC), 2021, : 60 - 71
  • [30] Moving target defense in distributed systems
    Shetty S.
    Yuchi X.
    Song M.
    Wireless Networks, 2016, 0 : 1 - 11