Dynamic security metrics for measuring the effectiveness of moving target defense techniques

被引:19
|
作者
Hong, Jin B. [1 ]
Enoch, Simon Yusuf [2 ]
Kim, Dong Seong [2 ]
Nhlabatsi, Armstrong [3 ]
Fetais, Noora [3 ]
Khan, Khaled M. [3 ]
机构
[1] Univ Western Australia, Dept Comp Sci & Software Engn, Nedlands, WA, Australia
[2] Univ Canterbury, Dept Comp Sci & Software Engn, Christchurch, New Zealand
[3] Qatar Univ, Dept Comp Sci & Engn, KINDI Comp Lab, Doha, Qatar
关键词
Emerging networking technology; Moving target defense; Security analysis; Security metric; Security model; SURVIVABILITY;
D O I
10.1016/j.cose.2018.08.003
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Moving Target Defense (MTD) utilizes granularity, flexibility and elasticity properties of emerging networking technologies in order to continuously change the attack surface. There are many different MTD techniques proposed in the past decade to thwart cyberattacks. Due to the diverse range of different MTD techniques, it is of paramount importance to assess and compare their effectiveness. However, each technique causes distinct (dynamic) changes in the network, making an objective comparison difficult. In this paper, we incorporate MTD techniques into a temporal graph-based graphical security model, and develop a new set of dynamic security metrics to assess and compare their effectiveness. To this end, we first categorize and compare different attack and defense efforts. Second, we describe the temporal graph-based graphical security model to capture dynamic changes made by various MTD techniques in the network. We then develop a new set of security metrics for attack and defense efforts to evaluate the effectiveness of the MTD techniques. We implement two different MTD techniques, namely network topology shuffle and software diversity, and show their effectiveness against a targeted attack scenario in our experimental analysis. The results demonstrate that the proposed dynamic security metrics can capture different properties of MTD techniques, permitting a more fine-grained comparison and offering guidance for selecting the most effective MTD technique. (C) 2018 Elsevier Ltd. All rights reserved.
引用
收藏
页码:33 / 52
页数:20
相关论文
共 50 条
  • [21] Assessing the Effectiveness of Moving Target Defenses Using Security Models
    Hong, Jin B.
    Kim, Dong Seong
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2016, 13 (02) : 163 - 177
  • [22] Lightweight Security for IoT Systems leveraging Moving Target Defense and Intrusion Detection
    Van-Tien Nguyen
    Navas, Renzo E.
    Doyen, Guillaume
    PROCEEDINGS OF 2024 IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM, NOMS 2024, 2024,
  • [23] Moving-Target-Defense based Security Mechanisms: A System Management Perspective
    Ravindran, Kaliappa
    Iannelli, Michael
    Adiththan, Arun
    2023 15TH INTERNATIONAL CONFERENCE ON COMMUNICATION SYSTEMS & NETWORKS, COMSNETS, 2023,
  • [24] Dynamic Generation Containment Systems (DGCS): A Moving Target Defense Approach
    Chin, Tommy
    Xiong, Kaiqi
    2016 3RD INTERNATIONAL WORKSHOP ON EMERGING IDEAS AND TRENDS IN ENGINEERING OF CYBER-PHYSICAL SYSTEMS (EITEC), 2016, : 11 - 16
  • [25] Explicit Analysis on Effectiveness and Hiddenness of Moving Target Defense in AC Power Systems
    Liu, Mengxiang
    Zhao, Chengcheng
    Zhang, Zhenyong
    Deng, Ruilong
    IEEE TRANSACTIONS ON POWER SYSTEMS, 2022, 37 (06) : 4732 - 4746
  • [26] Effectiveness of IP Address Randomization in Decoy-Based Moving Target Defense
    Clark, Andrew
    Sun, Kun
    Poovendran, Radha
    2013 IEEE 52ND ANNUAL CONFERENCE ON DECISION AND CONTROL (CDC), 2013, : 678 - 685
  • [27] Effectiveness Evaluation Model of Moving Target Defense Based on System Attack Surface
    Xiong, Xin-Li
    Yang, Lin
    Zhao, Guang-Sheng
    IEEE ACCESS, 2019, 7 : 9998 - 10014
  • [28] The Impact of Address Changes and Host Diversity on the Effectiveness of Moving Target Defense Strategy
    Zheng, Jianjun
    Namin, Akbar Siami
    PROCEEDINGS 2016 IEEE 40TH ANNUAL COMPUTER SOFTWARE AND APPLICATIONS CONFERENCE WORKSHOPS (COMPSAC), VOL 2, 2016, : 553 - 558
  • [29] Optimal Planning and Operation of Hidden Moving Target Defense for Maximal Detection Effectiveness
    Liu, Bo
    Wu, Hongyu
    IEEE TRANSACTIONS ON SMART GRID, 2021, 12 (05) : 4447 - 4459
  • [30] On Effectiveness of Detecting FDI Attacks on Power Grid using Moving Target Defense
    Zhang, Zhenyong
    Deng, Ruilong
    Yau, David
    Cheng, Peng
    Chen, Jiming
    2019 IEEE POWER & ENERGY SOCIETY INNOVATIVE SMART GRID TECHNOLOGIES CONFERENCE (ISGT), 2019,