Dynamic security metrics for measuring the effectiveness of moving target defense techniques

被引:19
|
作者
Hong, Jin B. [1 ]
Enoch, Simon Yusuf [2 ]
Kim, Dong Seong [2 ]
Nhlabatsi, Armstrong [3 ]
Fetais, Noora [3 ]
Khan, Khaled M. [3 ]
机构
[1] Univ Western Australia, Dept Comp Sci & Software Engn, Nedlands, WA, Australia
[2] Univ Canterbury, Dept Comp Sci & Software Engn, Christchurch, New Zealand
[3] Qatar Univ, Dept Comp Sci & Engn, KINDI Comp Lab, Doha, Qatar
关键词
Emerging networking technology; Moving target defense; Security analysis; Security metric; Security model; SURVIVABILITY;
D O I
10.1016/j.cose.2018.08.003
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Moving Target Defense (MTD) utilizes granularity, flexibility and elasticity properties of emerging networking technologies in order to continuously change the attack surface. There are many different MTD techniques proposed in the past decade to thwart cyberattacks. Due to the diverse range of different MTD techniques, it is of paramount importance to assess and compare their effectiveness. However, each technique causes distinct (dynamic) changes in the network, making an objective comparison difficult. In this paper, we incorporate MTD techniques into a temporal graph-based graphical security model, and develop a new set of dynamic security metrics to assess and compare their effectiveness. To this end, we first categorize and compare different attack and defense efforts. Second, we describe the temporal graph-based graphical security model to capture dynamic changes made by various MTD techniques in the network. We then develop a new set of security metrics for attack and defense efforts to evaluate the effectiveness of the MTD techniques. We implement two different MTD techniques, namely network topology shuffle and software diversity, and show their effectiveness against a targeted attack scenario in our experimental analysis. The results demonstrate that the proposed dynamic security metrics can capture different properties of MTD techniques, permitting a more fine-grained comparison and offering guidance for selecting the most effective MTD technique. (C) 2018 Elsevier Ltd. All rights reserved.
引用
收藏
页码:33 / 52
页数:20
相关论文
共 50 条
  • [1] Dynamic Security Metrics for Software-Defined Network-based Moving Target Defense
    Sharma, Dilli P.
    Enoch, Simon Yusuf
    Cho, Jin-Hee
    Moore, Terrence J.
    Nelson, Frederica F.
    Lim, Hyuk
    Kim, Dong Seong
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2020, 170
  • [2] Evaluating the Security and Economic Effects of Moving Target Defense Techniques on the Cloud
    Alavizadeh, Hooman
    Aref, Samin
    Kim, Dong Seong
    Jang-Jaccard, Julian
    IEEE TRANSACTIONS ON EMERGING TOPICS IN COMPUTING, 2022, 10 (04) : 1772 - 1788
  • [3] Moving Target Defense Techniques: A Survey
    Lei, Cheng
    Zhang, Hong-Qi
    Tan, Jing-Lei
    Zhang, Yu-Chen
    Liu, Xiao-Hu
    SECURITY AND COMMUNICATION NETWORKS, 2018,
  • [4] Effectiveness of Port Hopping as a Moving Target Defense
    Luo, Yue-Bin
    Wang, Bao-Sheng
    Cai, Gui-Lin
    2014 7TH INTERNATIONAL CONFERENCE ON SECURITY TECHNOLOGY (SECTECH), 2014, : 7 - 10
  • [5] A Model for Analyzing the Effectiveness of Moving Target Defense
    Zhao, Guangsheng
    Xiong, Xinli
    Wu, Huaying
    ICCNS 2018: PROCEEDINGS OF THE 8TH INTERNATIONAL CONFERENCE ON COMMUNICATION AND NETWORK SECURITY, 2018, : 17 - 21
  • [6] Toward Effectiveness and Agility of Network Security Situational Awareness Using Moving Target Defense (MTD)
    Ge, Linqiang
    Yu, Wei
    Shen, Dan
    Chen, Genshe
    Khanh Pham
    Blasch, Erik
    Lu, Chao
    SENSORS AND SYSTEMS FOR SPACE APPLICATIONS VII, 2014, 9085
  • [7] Moving Target Defense: A Symbiotic Framework for AI & Security
    Sengupta, Sailik
    AAMAS'17: PROCEEDINGS OF THE 16TH INTERNATIONAL CONFERENCE ON AUTONOMOUS AGENTS AND MULTIAGENT SYSTEMS, 2017, : 1861 - 1862
  • [8] A Moving Target Defense Security Solution for IoT Applications
    Kyriakakis, Thomas
    Ioannidis, Sotiris
    2023 19TH INTERNATIONAL CONFERENCE ON THE DESIGN OF RELIABLE COMMUNICATION NETWORKS, DRCN, 2023,
  • [9] Using Dynamic Addressing for a Moving Target Defense
    Groat, Stephen
    Dunlop, Matthew
    Marchany, Randy
    Tront, Joseph
    PROCEEDINGS OF THE 6TH INTERNATIONAL CONFERENCE ON INFORMATION WARFARE AND SECURITY, 2011, : 84 - 91
  • [10] Evaluating the Effectiveness of Security Metrics for Dynamic Networks
    Yusuf, Simon Enoch
    Ge, Mengmeng
    Hong, Jin B.
    Alzaid, Hani
    Kim, Dong Seong
    2017 16TH IEEE INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS / 11TH IEEE INTERNATIONAL CONFERENCE ON BIG DATA SCIENCE AND ENGINEERING / 14TH IEEE INTERNATIONAL CONFERENCE ON EMBEDDED SOFTWARE AND SYSTEMS, 2017, : 277 - 284