Effectiveness Evaluation Model of Moving Target Defense Based on System Attack Surface

被引:19
|
作者
Xiong, Xin-Li [1 ]
Yang, Lin [2 ]
Zhao, Guang-Sheng [3 ]
机构
[1] Army Engn Univ PLA, Coll Command & Control Engn, Nanjing 211101, Jiangsu, Peoples R China
[2] Acad Mil Sci PLA, Syst Engn Res Inst, Beijing 100141, Peoples R China
[3] Natl Univ Def Technol, Coll Comp Sci, Changsha 410073, Hunan, Peoples R China
来源
IEEE ACCESS | 2019年 / 7卷
关键词
Information security; moving target defense; nonhomogeneous hidden Markov processes; performance evaluation;
D O I
10.1109/ACCESS.2019.2891613
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Evaluation of moving target defense (MTD) effectiveness has become one of the fundamental problems in current studies. In this paper, an evaluation model of MTD effectiveness based on system attack surface (SAS) is proposed to extend this model covering enterprise-class topology and multi-layered moving target (MT) techniques. The model is focused on the problem of incorrect performance assessment caused by inaccurately characterizing the process of attacking and defending. Existing evaluation models often fail to describe M ID dynamically in a process. To deal with this static view, offensive and defensive process based on a player's move is presented. Besides, it converts all the attack and defense actions into the process, and interactivities are evaluated by system view extended attack surface model. Previously, the proposed attack surface models are not concerned about the links between nodes and vulnerabilities affected by topologies. After comprehensively analyzing the impact of interactions in the system, a SAS model is proposed to demonstrate how resources of the system are affected by the actions of attackers and defenders, thus ensuring the correctness of parameters for SAS in measuring MT technology. Moreover, by generating a sequence of those shifting parameters, a nonhomogeneous hierarchical hidden Markov model is used to find the possible sequence of attacking states by introducing the partial Viterbi algorithm. Also, a sequence of attacking states is defined to illustrate how adversaries are handled by MT technologies and how much additional consumption costs are increased by the system resource reconfiguration. Finally, the simulation of the proposed approach is given in a case study to demonstrate the feasibility and validity of the proposed effectiveness evaluation model in a systematic and dynamic view.
引用
收藏
页码:9998 / 10014
页数:17
相关论文
共 50 条
  • [1] Model-based Performance Evaluation of a Moving Target Defense System
    Chen, Zhi
    Chang, Xiaolin
    Misic, Jelena
    Misic, Vojislav B.
    Yang, Yang
    Han, Zhen
    2020 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2020,
  • [2] A Defense Method Based on Moving Target Defense for New Power System APT Attack
    Li, Ruotong
    Li, Yuancheng
    International Journal of Network Security, 2023, 25 (04) : 587 - 594
  • [3] Survey on Attack Surface Dynamic Transfer Technology Based on Moving Target Defense
    Zhou Y.-Y.
    Cheng G.
    Guo C.-S.
    Dai M.
    Ruan Jian Xue Bao/Journal of Software, 2018, 29 (09): : 2799 - 2820
  • [4] A Model for Analyzing the Effectiveness of Moving Target Defense
    Zhao, Guangsheng
    Xiong, Xinli
    Wu, Huaying
    ICCNS 2018: PROCEEDINGS OF THE 8TH INTERNATIONAL CONFERENCE ON COMMUNICATION AND NETWORK SECURITY, 2018, : 17 - 21
  • [5] Moving Target Defense Technique Based on Network Attack Surface Self-Adaptive Mutation
    Lei C.
    Ma D.-H.
    Zhang H.-Q.
    Yang Y.-J.
    Wang L.-M.
    Ma, Duo-He (maduohe@iie.ac.cn), 2018, Science Press (41): : 1109 - 1131
  • [6] Moving Target Network Defense Effectiveness Evaluation Based on Change-Point Detection
    Lei, Cheng
    Ma, Duo-he
    Zhang, Hong-qi
    Wang, Li-ming
    MATHEMATICAL PROBLEMS IN ENGINEERING, 2016, 2016
  • [7] Defending Blind DDoS Attack on SDN Based on Moving Target Defense
    Ma, Duohe
    Xu, Zhen
    Lin, Dongdai
    INTERNATIONAL CONFERENCE ON SECURITY AND PRIVACY IN COMMUNICATION NETWORKS, SECURECOMM 2014, PT I, 2015, 152 : 463 - 480
  • [8] Proactive attack detection scheme based on watermarking and moving target defense
    Liu, Hao
    Zhang, Yewei
    Li, Yuzhe
    Niu, Ben
    AUTOMATICA, 2023, 155
  • [9] System attack surface based MTD effectiveness assessment model
    Xiong X.
    Zhao G.
    Xu W.
    Li B.
    Qinghua Daxue Xuebao/Journal of Tsinghua University, 2019, 59 (04): : 276 - 283
  • [10] Effectiveness and Impact Measurements of a Diversification Based Moving Target Defense
    Smine, Manel
    Cuppens, Nora
    Cuppens, Frederic
    RISKS AND SECURITY OF INTERNET AND SYSTEMS, 2019, 11391 : 158 - 171