Attacker Skill, Defender Strategies and the Effectiveness of Migration-Based Moving Target Defense in Cyber Systems

被引:0
|
作者
Ben-Asher, Noam [1 ,2 ]
Morris-King, James [2 ]
Thompson, Brian [2 ]
Glodek, William [3 ]
机构
[1] IBM TJ Watson Res Ctr, Yorktown Hts, NY 10598 USA
[2] US Army, Res Lab, Adelphi, MD 20783 USA
[3] BreakPoint Labs, Dunn Loring, VA USA
关键词
moving target defense; platform diversity; platform migration; attacker skill; modeling; reconnaissance; exploit; cyber-attack;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Despite the significant effort directed toward securing important cyber systems, many remain vulnerable to advanced, targeted cyber intrusion. Today, most systems that provide network services employ a fixed software stack that typically includes an operating system, web servers, and database software. This software mix as a whole constitutes the attack surface of the host, and a vulnerability in one or more of its components is a threat to the security of the entire system. Moving target defense (MTD) aims to increase the security of a system against successful intrusion by increasing an attacker's uncertainty of the attack surface. Platform migration defense (PMD) is a form of MTD that entails changing the software stack of a system. We consider a scenario in which an attacker gathers information and then selects and launches an attack against a target system that is using PMD. We perform simulations using a multi-agent model to evaluate the effectiveness of PMD against a spectrum of attackers ranging from "script-kiddies" to state-sponsored actors. In particular, we focus on two core characteristics of PMD: (i) migration rate, the frequency at which the platform is changed, and (ii) platform diversity, the number of platform configurations available, as well as two dimensions of an attacker's capabilities: (i) reconnaissance skill, the ability to collect accurate information regarding the target system, and (ii) arsenal size, the number of usable exploits at the attacker's disposal. Our results indicate that increasing migration rate and platform diversity results in a lower rate of successful attacks, even in cases where the attacker has near-perfect information regarding the target system, but that this may come at a cost in system performance. Furthermore, although the strength of an attacker is often measured by their ability to develop or acquire a large arsenal of available exploits, reconnaissance skill may be just as important a determinant for the success of an attack as the arsenal size. Our analysis provides insight into the relationship between attacker and defender capabilities, which can help inform decision-making processes of cyber defenders and lay the grounds for effective automation of cyber maneuvers.
引用
收藏
页码:21 / 30
页数:10
相关论文
共 33 条
  • [1] On the effectiveness of migration-based load balancing strategies in DHT systems
    Wu, Di
    Tian, Ye
    Ng, Kam-Wing
    ICCCN 2006: 15TH INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATIONS AND NETWORKS, PROCEEDINGS, 2006, : 405 - +
  • [2] Cyber security based on mean field game model of the defender: Attacker strategies
    Miao, Li
    Li, Shuai
    INTERNATIONAL JOURNAL OF DISTRIBUTED SENSOR NETWORKS, 2017, 13 (10): : 1 - 8
  • [3] A Moving Target Defense for Securing Cyber-Physical Systems
    Griffioen, Paul
    Weerakkody, Sean
    Sinopoli, Bruno
    IEEE TRANSACTIONS ON AUTOMATIC CONTROL, 2021, 66 (05) : 2016 - 2031
  • [4] A Moving Target Defense Control Framework for Cyber-Physical Systems
    Kanellopoulos, Aris
    Vamvoudakis, Kyriakos G.
    IEEE TRANSACTIONS ON AUTOMATIC CONTROL, 2020, 65 (03) : 1029 - 1043
  • [5] A Cyber Risk Based Moving Target Defense Mechanism for Microservice Architectures
    Torkura, Kennedy A.
    Sukmana, Muhammad I. H.
    Kayem, Anne V. D. M.
    Cheng, Feng
    Meinel, Christoph
    2018 IEEE INT CONF ON PARALLEL & DISTRIBUTED PROCESSING WITH APPLICATIONS, UBIQUITOUS COMPUTING & COMMUNICATIONS, BIG DATA & CLOUD COMPUTING, SOCIAL COMPUTING & NETWORKING, SUSTAINABLE COMPUTING & COMMUNICATIONS, 2018, : 932 - 939
  • [6] A Moving Target Defense to Detect Stealthy Attacks in Cyber-Physical Systems
    Giraldo, J.
    Cardenas, A.
    Sanfelice, R. G.
    2019 AMERICAN CONTROL CONFERENCE (ACC), 2019, : 391 - 396
  • [7] Reputation-based Service Migration for Moving Target Defense
    Zuo, Yanjun
    2016 IEEE INTERNATIONAL CONFERENCE ON ELECTRO INFORMATION TECHNOLOGY (EIT), 2016, : 239 - 245
  • [8] Effectiveness and Impact Measurements of a Diversification Based Moving Target Defense
    Smine, Manel
    Cuppens, Nora
    Cuppens, Frederic
    RISKS AND SECURITY OF INTERNET AND SYSTEMS, 2019, 11391 : 158 - 171
  • [9] Morphing Communications of Cyber-Physical Systems Towards Moving-Target Defense
    Li, Yu
    Dai, Rui
    Zhang, Junjie
    2014 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2014, : 592 - 598
  • [10] A Tutorial on Moving Target Defense Approaches Within Automotive Cyber-Physical Systems
    Potteiger, Bradley
    Zhang, Zhenkai
    Cheng, Long
    Koutsoukos, Xenofon
    FRONTIERS IN FUTURE TRANSPORTATION, 2022, 2