Moving Target Defense for Securing SCADA Communications

被引:15
|
作者
Heydari, Vahid [1 ]
机构
[1] Rowan Univ, Comp Sci Dept, Glassboro, NJ 08028 USA
来源
IEEE ACCESS | 2018年 / 6卷
关键词
SCADA; mobile IPv6; moving target defense; dynamic IP; ATTACKS;
D O I
10.1109/ACCESS.2018.2844542
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In this paper, we introduce a framework for building a secure and private peer to peer communication used in supervisory control and data acquisition networks with a novel Mobile IPv6-based moving target defense strategy. Our approach aids in combating remote cyber-attacks against peer hosts by thwarting any potential attacks at their reconnaissance stage. The IP address of each host is randomly changed at a certain interval creating a moving target to make it difficult for an attacker to find the host. At the same time, the peer host is updated through the use of the binding update procedure (standard Mobile IPv6 protocol). Compared with existing results that can incur significant packet-loss during address rotations, the proposed solution is loss-less. Improving privacy and anonymity for communicating hosts by removing permanent IP addresses from all packets is also one of the major contributions of this paper. Another contribution is preventing black hole attacks and bandwidth depletion DDoS attacks through the use of extra paths between the peer hosts. Recovering the communication after rebooting a host is also a new contribution of this paper. Lab-based simulation results are presented to demonstrate the performance of the method in action, including its overheads. The testbed experiments show zero packet-loss rate during handoff delay.
引用
收藏
页码:33329 / 33343
页数:15
相关论文
共 50 条
  • [41] Turtle Consensus: Moving Target Defense for Consensus
    Nikolaou, Stavros
    Van Renesse, Robbert
    PROCEEDINGS OF THE 16TH ANNUAL MIDDLEWARE CONFERENCE, 2015, : 185 - 196
  • [42] Web Deception towards Moving Target Defense
    Djamaluddin, Basirudin
    Alnazeer, Ahmed
    Azzedin, Farag
    2018 52ND ANNUAL IEEE INTERNATIONAL CARNAHAN CONFERENCE ON SECURITY TECHNOLOGY (ICCST), 2018, : 249 - 253
  • [43] Research and development of moving target defense technology
    Cai G.
    Wang B.
    Wang T.
    Luo Y.
    Wang X.
    Cui X.
    Jisuanji Yanjiu yu Fazhan/Computer Research and Development, 2016, 53 (05): : 968 - 987
  • [44] Effectiveness of Port Hopping as a Moving Target Defense
    Luo, Yue-Bin
    Wang, Bao-Sheng
    Cai, Gui-Lin
    2014 7TH INTERNATIONAL CONFERENCE ON SECURITY TECHNOLOGY (SECTECH), 2014, : 7 - 10
  • [45] Repeatable Experimentation for Cybersecurity Moving Target Defense
    Acosta, Jaime C.
    Clarke, Luisana
    Medina, Stephanie
    Akbar, Monika
    Hossain, Mahmud Shahriar
    Free-Nelson, Frederica
    SECURITY AND PRIVACY IN COMMUNICATION NETWORKS, SECURECOMM 2021, PT I, 2021, 398 : 82 - 99
  • [46] Moving target defense:state of the art and characteristics
    Gui-lin CAI
    Bao-sheng WANG
    Wei HU
    Tian-zuo WANG
    FrontiersofInformationTechnology&ElectronicEngineering, 2016, 17 (11) : 1122 - 1153
  • [47] A Model for Analyzing the Effectiveness of Moving Target Defense
    Zhao, Guangsheng
    Xiong, Xinli
    Wu, Huaying
    ICCNS 2018: PROCEEDINGS OF THE 8TH INTERNATIONAL CONFERENCE ON COMMUNICATION AND NETWORK SECURITY, 2018, : 17 - 21
  • [48] Enforcing Optimal Moving Target Defense Policies
    Zheng, Jianjun
    Namin, Akbar Siami
    2019 IEEE 43RD ANNUAL COMPUTER SOFTWARE AND APPLICATIONS CONFERENCE (COMPSAC), VOL 1, 2019, : 753 - 759
  • [49] Research on moving target defense based on SDN
    Chen, Mingyong
    Wu, Weimin
    GREEN ENERGY AND SUSTAINABLE DEVELOPMENT I, 2017, 1864
  • [50] Moving target defense: state of the art and characteristics
    Gui-lin Cai
    Bao-sheng Wang
    Wei Hu
    Tian-zuo Wang
    Frontiers of Information Technology & Electronic Engineering, 2016, 17 : 1122 - 1153