Moving Target Defense for In-Vehicle Software-Defined Networking: IP Shuffling in Network Slicing with Multiagent Deep Reinforcement Learning

被引:5
|
作者
Yoon, Seunghyun [1 ]
Cho, Jin-Hee [2 ]
Kim, Dong Seong [3 ]
Moore, Terrence J. [4 ]
Nelson, Frederica F. [4 ]
Lim, Hyuk [1 ]
Leslie, Nandi [4 ]
Kamhoua, Charles A. [4 ]
机构
[1] Gwangju Inst Sci & Technol, Gwangju, South Korea
[2] Virginia Tech, Falls Church, VA USA
[3] Univ Queensland, Brisbane, Qld, Australia
[4] US Army, Res Lab, Adelphi, MD USA
关键词
Moving target defense (MTD); IP shuffling; software-defined networking (SDN); network slicing; in-vehicle network; deep reinforcement learning (DRL); multi-agent system; multi-agent DRL;
D O I
10.1117/12.2557850
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Moving target defense (MTD) is an emerging defense principle that aims to dynamically change attack surface to confuse attackers. By dynamic reconfiguration, MTD intends to invalidate the attacker's intelligence or information collection during reconnaissance, resulting in wasted resources and high attack cost/complexity for the attacker. One of the key merits of MTD is its capability to offer 'affordable defense,' by working with legacy defense mechanisms, such as intrusion detection systems (IDS) or other cryptographic mechanisms. On the other hand, a well-known drawback of MTD is the additional overhead, such as reconfiguration cost and/or potential interruptions of service availability to normal users. In this work, we aim to develop a highly secure, resilient, and affordable MTD-based proactive defense mechanism, which achieves multiple objectives of minimizing system security vulnerabilities and defense cost while maximizing service availability. To this end, we propose a multi-agent Deep Reinforcement Learning (mDRL)-based network slicing technique that can help determine two key resource management decisions: (1) link bandwidth allocation to meet Quality-of-Service requirements and (2) the frequency of triggering IP shuffling as an MTD operation not to hinder service availability by maintaining normal system operations. Specifically, we apply this strategy in an in-vehicle network that uses software-defined networking (SDN) technology to deploy the IP shuffling-based MTD, which dynamically changes IP addresses assigned to electronic control unit (ECU) nodes to introduce uncertainty or confusion for attackers.
引用
收藏
页数:10
相关论文
共 50 条
  • [1] Poster: Address Shuffling based Moving Target Defense for In-Vehicle Software-Defined Networks
    Yoon, Seunghyun
    Cho, Jin-Hee
    Kim, Dong Seong
    Moore, Terrence J.
    Nelson, Frederica
    Lim, Hyuk
    [J]. MOBICOM'19: PROCEEDINGS OF THE 25TH ANNUAL INTERNATIONAL CONFERENCE ON MOBILE COMPUTING AND NETWORKING, 2019,
  • [2] Look Again, Neo: A Software-Defined Networking Moving Target Defense
    Mayer, Samuel
    Reith, Mark
    Mullins, Barry
    [J]. PROCEEDINGS OF THE 13TH INTERNATIONAL CONFERENCE ON CYBER WARFARE AND SECURITY (ICCWS 2018), 2018, : 602 - 610
  • [3] Frequency-Minimal Moving Target Defense using Software-Defined Networking
    Debroy, Saptarshi
    Calyam, Prasad
    Nguyen, Minh
    Stage, Allen
    Georgiev, Vladimir
    [J]. 2016 INTERNATIONAL CONFERENCE ON COMPUTING, NETWORKING AND COMMUNICATIONS (ICNC), 2016,
  • [4] Moving Target Defense Against Network Reconnaissance with Software Defined Networking
    Wang, Li
    Wu, Dinghao
    [J]. INFORMATION SECURITY, (ISC 2016), 2016, 9866 : 203 - 217
  • [5] DRSIR: A Deep Reinforcement Learning Approach for Routing in Software-Defined Networking
    Casas-Velasco, Daniela M.
    Rendon, Oscar Mauricio Caicedo
    da Fonseca, Nelson L. S.
    [J]. IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2022, 19 (04): : 4807 - 4820
  • [6] Performance and Security Evaluation of a Moving Target Defense Based on a Software-Defined Networking Environment
    Kim, Minjune
    Cho, Jin-Hee
    Lim, Hyuk
    Moore, Terrence J.
    Nelson, Frederica F.
    Kim, Dan Dongseong
    [J]. 2022 IEEE 27TH PACIFIC RIM INTERNATIONAL SYMPOSIUM ON DEPENDABLE COMPUTING (PRDC), 2022, : 119 - 129
  • [7] Towards Dynamically Shifting Cyber Terrain With Software-Defined Networking and Moving Target Defense
    Larkin, Robert
    Jensen, Steven
    Koranek, Daniel
    Mullins, Barry
    Reith, Mark
    [J]. PROCEEDINGS OF THE 16TH INTERNATIONAL CONFERENCE ON CYBER WARFARE AND SECURITY (ICCWS 2021), 2021, : 535 - 540
  • [8] EVADE: Efficient Moving Target Defense for Autonomous Network Topology Shuffling Using Deep Reinforcement Learning
    Zhang, Qisheng
    Cho, Jin-Hee
    Moore, Terrence J.
    Kim, Dan Dongseong
    Lim, Hyuk
    Nelson, Frederica
    [J]. APPLIED CRYPTOGRAPHY AND NETWORK SECURITY, PT I, ACNS 2023, 2023, 13905 : 555 - 582
  • [9] Reinforcement Learning for Autonomous Defence in Software-Defined Networking
    Han, Yi
    Rubinstein, Benjamin I. P.
    Abraham, Tamas
    Alpcan, Tansu
    De Vel, Olivier
    Erfani, Sarah
    Hubczenko, David
    Leckie, Christopher
    Montague, Paul
    [J]. DECISION AND GAME THEORY FOR SECURITY, GAMESEC 2018, 2018, 11199 : 145 - 165
  • [10] POSTER: Toward Intelligent Cyber Attacks for Moving Target Defense Techniques in Software-Defined Networking
    Moghaddam, Tina
    Yang, Guowei
    Thapa, Chandra
    Camtepe, Seyit
    Kim, Dan Dongseong
    [J]. PROCEEDINGS OF THE 2023 ACM ASIA CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, ASIA CCS 2023, 2023, : 1022 - 1024