A Software-Defined Approach for Mitigating Insider and External Threats via Moving Target Defense

被引:2
|
作者
d'Ambrosio, Nicola [1 ]
Melluso, Emma [1 ]
Perrone, Gaetano [1 ]
Romano, Simon Pietro [1 ]
机构
[1] Univ Naples Federico II, Dept Elect Engn & Informat Technol, Naples, Italy
关键词
Moving Target Defense; Active Deception; Honeynet; Software Defined Network; Insider Threats;
D O I
10.1109/NFV-SDN59219.2023.10329613
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
In cyberspace conflicts, defenders face a significant disadvantage. A single mistake in a defense strategy could irreparably compromise a network infrastructure, while attackers can persistently search for vulnerabilities to exploit. Moreover, adversaries can learn from their errors and refine their methods for subsequent attempts. To bridge this gap, deception techniques such as Active Deception (AD) and Moving Target Defense (MTD) have been introduced as an additional layer of defense to enhance traditional cyber-defense strategies. These techniques aim to deceive attackers, detect their activities, and gather intelligence on their attack methodologies. Existing literature focuses on mitigating specific adversarial strategies, such as scanning or service exploitation, rather than providing a comprehensive defense mechanism against diverse threats from both internal and external sources. To tackle this challenge, our approach leverages the combined capabilities of MTD and honeypots to bolster the security of an enterprise network and gain valuable insights into the attacker's behavior. The system accurately detects the attacker's scanning and exploitation activities, redirecting all their connections towards a Honeynet for further analysis and protection of critical assets. Additionally, proactive and reactive port hopping techniques are strategically employed to confuse and mislead the attacker. Through the implementation of these techniques, our goal is to fortify network defenses, increase the complexity faced by potential attackers, and acquire valuable knowledge about their tactics.
引用
收藏
页码:213 / 219
页数:7
相关论文
共 50 条
  • [41] Defense Against Software-Defined Network Topology Poisoning Attacks
    Gao, Yang
    Xu, Mingdi
    TSINGHUA SCIENCE AND TECHNOLOGY, 2023, 28 (01): : 39 - 46
  • [42] Timing-based Reconnaissance and Defense in Software-defined Networks
    Sonchack, John
    Dubey, Anurag
    Aviv, Adam J.
    Smith, Jonathan M.
    Keller, Eric
    32ND ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE (ACSAC 2016), 2016, : 89 - 100
  • [43] Packet Injection Attack and Its Defense in Software-Defined Networks
    Deng, Shuhua
    Gao, Xing
    Lu, Zebin
    Gao, Xieping
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2018, 13 (03) : 695 - 705
  • [44] Software-defined Networking-based DDoS Defense Mechanisms
    Swami, Rochak
    Dave, Mayank
    Ranga, Virender
    ACM COMPUTING SURVEYS, 2019, 52 (02)
  • [45] DoSGuard: Mitigating Denial-of-Service Attacks in Software-Defined Networks
    Li, Jishuai
    Tu, Tengfei
    Li, Yongsheng
    Qin, Sujuan
    Shi, Yijie
    Wen, Qiaoyan
    SENSORS, 2022, 22 (03)
  • [46] SNIPS: A Software-Defined Approach for Scaling Intrusion Prevention Systems via Offloading
    Heorhiadi, Victor
    Fayaz, Seyed Kaveh
    Reiter, Michael K.
    Sekar, Vyas
    INFORMATION SYSTEMS SECURITY (ICISS 2014), 2014, 8880 : 9 - 29
  • [47] Development and Approach to Software-defined Radio Technology
    Kimitaka, Nagata
    Satoshi, Seki
    Kenji, Minami
    Makoto, Oka
    Yasuo, Ishii
    Masatoshi, Sugata
    NEC Technical Journal, 2021, 16 (01): : 112 - 116
  • [48] A SOFTWARE-DEFINED RADIO APPROACH FOR DIRECTION FINDING
    Paun, Mirel
    Tamas, Razvan
    Marghescu, Ion
    UNIVERSITY POLITEHNICA OF BUCHAREST SCIENTIFIC BULLETIN SERIES C-ELECTRICAL ENGINEERING AND COMPUTER SCIENCE, 2015, 77 (04): : 235 - 244
  • [49] An approach for deployment of BRS in software-defined network
    Dutta, Parinita
    Chatterjee, Rajeev
    Mandal, Jyotsna Kumar
    INNOVATIONS IN SYSTEMS AND SOFTWARE ENGINEERING, 2019, 15 (3-4) : 355 - 361
  • [50] A FIRM Approach for Software-Defined Service Composition
    Kathiravelu, Pradeeban
    Grbac, Tihana Galinac
    Veiga, Luis
    2016 39TH INTERNATIONAL CONVENTION ON INFORMATION AND COMMUNICATION TECHNOLOGY, ELECTRONICS AND MICROELECTRONICS (MIPRO), 2016, : 565 - 570