Attacker Skill, Defender Strategies and the Effectiveness of Migration-Based Moving Target Defense in Cyber Systems

被引:0
|
作者
Ben-Asher, Noam [1 ,2 ]
Morris-King, James [2 ]
Thompson, Brian [2 ]
Glodek, William [3 ]
机构
[1] IBM TJ Watson Res Ctr, Yorktown Hts, NY 10598 USA
[2] US Army, Res Lab, Adelphi, MD 20783 USA
[3] BreakPoint Labs, Dunn Loring, VA USA
关键词
moving target defense; platform diversity; platform migration; attacker skill; modeling; reconnaissance; exploit; cyber-attack;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Despite the significant effort directed toward securing important cyber systems, many remain vulnerable to advanced, targeted cyber intrusion. Today, most systems that provide network services employ a fixed software stack that typically includes an operating system, web servers, and database software. This software mix as a whole constitutes the attack surface of the host, and a vulnerability in one or more of its components is a threat to the security of the entire system. Moving target defense (MTD) aims to increase the security of a system against successful intrusion by increasing an attacker's uncertainty of the attack surface. Platform migration defense (PMD) is a form of MTD that entails changing the software stack of a system. We consider a scenario in which an attacker gathers information and then selects and launches an attack against a target system that is using PMD. We perform simulations using a multi-agent model to evaluate the effectiveness of PMD against a spectrum of attackers ranging from "script-kiddies" to state-sponsored actors. In particular, we focus on two core characteristics of PMD: (i) migration rate, the frequency at which the platform is changed, and (ii) platform diversity, the number of platform configurations available, as well as two dimensions of an attacker's capabilities: (i) reconnaissance skill, the ability to collect accurate information regarding the target system, and (ii) arsenal size, the number of usable exploits at the attacker's disposal. Our results indicate that increasing migration rate and platform diversity results in a lower rate of successful attacks, even in cases where the attacker has near-perfect information regarding the target system, but that this may come at a cost in system performance. Furthermore, although the strength of an attacker is often measured by their ability to develop or acquire a large arsenal of available exploits, reconnaissance skill may be just as important a determinant for the success of an attack as the arsenal size. Our analysis provides insight into the relationship between attacker and defender capabilities, which can help inform decision-making processes of cyber defenders and lay the grounds for effective automation of cyber maneuvers.
引用
收藏
页码:21 / 30
页数:10
相关论文
共 33 条
  • [21] Moving Target Defense for Cyber-Physical Systems Using IoT-Enabled Data Replication
    Giraldo, Jairo A.
    El Hariri, Mohamad
    Parvania, Masood
    IEEE INTERNET OF THINGS JOURNAL, 2022, 9 (15): : 13223 - 13232
  • [22] Proactive defense mechanism: Enhancing IoT security through diversity-based moving target defense and cyber deception
    Rehman, Zubaida
    Gondal, Iqbal
    Ge, Mengmeng
    Dong, Hai
    Gregory, Mark
    Tari, Zahir
    COMPUTERS & SECURITY, 2024, 139
  • [23] MTD CBITS: Moving Target Defense for Cloud-Based IT Systems
    Bardas, Alexandru G.
    Sundaramurthy, Sathya Chandran
    Ou, Xinming
    DeLoach, Scott A.
    COMPUTER SECURITY - ESORICS 2017, PT I, 2018, 10492 : 167 - 186
  • [24] Moving Target Defense Based on Adaptive Forwarding Path Migration for Securing the SCADA Network
    Hu, Yifan
    Xun, Peng
    Zhu, Peidong
    Kang, Wenjie
    Xiong, Yinqiao
    Zhu, Yufei
    Shi, Weiheng
    Hu, Chenxi
    SECURITY AND COMMUNICATION NETWORKS, 2021, 2021
  • [25] Moving Target Network Defense Effectiveness Evaluation Based on Change-Point Detection
    Lei, Cheng
    Ma, Duo-he
    Zhang, Hong-qi
    Wang, Li-ming
    MATHEMATICAL PROBLEMS IN ENGINEERING, 2016, 2016
  • [26] Decoy-based Moving Target defense Against Cyber-physical Attacks On Smart Grid
    Abdelwahab, Ahmed
    Lucia, Walter
    Youssef, Amr
    2020 IEEE ELECTRIC POWER AND ENERGY CONFERENCE (EPEC), 2020,
  • [27] A switching-based Moving Target Defense against sensor attacks in control systems
    Giraldo, J.
    Cardenas, A.
    Sanfelice, R. G.
    NONLINEAR ANALYSIS-HYBRID SYSTEMS, 2023, 47
  • [28] Event-Based Moving Target Defense in Cloud Computing with VM Migration: A Performance Modeling Approach
    Santos L.
    Brito C.
    Fe I.
    Carvalho J.
    Torquato M.
    Choi E.
    Min D.
    Lee J.
    Nguyen T.A.
    Silva F.A.
    IEEE Access, 2024, 12 : 1 - 1
  • [29] Software Rejuvenation Meets Moving Target Defense: Modeling of Time-Based Virtual Machine Migration Approach
    Torquato, Matheus
    Maciel, Paulo
    Vieira, Marco
    2022 IEEE 33RD INTERNATIONAL SYMPOSIUM ON SOFTWARE RELIABILITY ENGINEERING (ISSRE 2022), 2022, : 205 - 216
  • [30] Model-Based Design of Defense Cyber-Physical Systems to Analyze Mission Effectiveness and Network Performance
    Kang, Bong Gu
    Seo, Kyung-Min
    Kim, Tag Gon
    IEEE ACCESS, 2019, 7 : 42063 - 42080