Dynamic security metrics for measuring the effectiveness of moving target defense techniques

被引:19
|
作者
Hong, Jin B. [1 ]
Enoch, Simon Yusuf [2 ]
Kim, Dong Seong [2 ]
Nhlabatsi, Armstrong [3 ]
Fetais, Noora [3 ]
Khan, Khaled M. [3 ]
机构
[1] Univ Western Australia, Dept Comp Sci & Software Engn, Nedlands, WA, Australia
[2] Univ Canterbury, Dept Comp Sci & Software Engn, Christchurch, New Zealand
[3] Qatar Univ, Dept Comp Sci & Engn, KINDI Comp Lab, Doha, Qatar
关键词
Emerging networking technology; Moving target defense; Security analysis; Security metric; Security model; SURVIVABILITY;
D O I
10.1016/j.cose.2018.08.003
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Moving Target Defense (MTD) utilizes granularity, flexibility and elasticity properties of emerging networking technologies in order to continuously change the attack surface. There are many different MTD techniques proposed in the past decade to thwart cyberattacks. Due to the diverse range of different MTD techniques, it is of paramount importance to assess and compare their effectiveness. However, each technique causes distinct (dynamic) changes in the network, making an objective comparison difficult. In this paper, we incorporate MTD techniques into a temporal graph-based graphical security model, and develop a new set of dynamic security metrics to assess and compare their effectiveness. To this end, we first categorize and compare different attack and defense efforts. Second, we describe the temporal graph-based graphical security model to capture dynamic changes made by various MTD techniques in the network. We then develop a new set of security metrics for attack and defense efforts to evaluate the effectiveness of the MTD techniques. We implement two different MTD techniques, namely network topology shuffle and software diversity, and show their effectiveness against a targeted attack scenario in our experimental analysis. The results demonstrate that the proposed dynamic security metrics can capture different properties of MTD techniques, permitting a more fine-grained comparison and offering guidance for selecting the most effective MTD technique. (C) 2018 Elsevier Ltd. All rights reserved.
引用
收藏
页码:33 / 52
页数:20
相关论文
共 50 条
  • [41] Survey on Attack Surface Dynamic Transfer Technology Based on Moving Target Defense
    Zhou Y.-Y.
    Cheng G.
    Guo C.-S.
    Dai M.
    Ruan Jian Xue Bao/Journal of Software, 2018, 29 (09): : 2799 - 2820
  • [42] Information security: The moving target
    Dlamini, M. T.
    Eloff, J. H. P.
    Eloff, M. M.
    COMPUTERS & SECURITY, 2009, 28 (3-4) : 189 - 198
  • [43] Moving Target Network Defense Effectiveness Evaluation Based on Change-Point Detection
    Lei, Cheng
    Ma, Duo-he
    Zhang, Hong-qi
    Wang, Li-ming
    MATHEMATICAL PROBLEMS IN ENGINEERING, 2016, 2016
  • [44] Moving Target Defense Router: MaTaDoR
    Ufuk, Berkan
    Sandikkaya, Mehmet Tahir
    SECRYPT : PROCEEDINGS OF THE 19TH INTERNATIONAL CONFERENCE ON SECURITY AND CRYPTOGRAPHY, 2022, : 649 - 654
  • [46] A Framework for Moving Target Defense Quantification
    Connell, Warren
    Albanese, Massimiliano
    Venkatesan, Sridhar
    ICT SYSTEMS SECURITY AND PRIVACY PROTECTION, SEC 2017, 2017, 502 : 124 - 138
  • [47] Overview on Moving Target Network Defense
    Zhou, Xuan
    Lu, Yuliang
    Wang, Yongjie
    Yan, Xuehu
    2018 IEEE 3RD INTERNATIONAL CONFERENCE ON IMAGE, VISION AND COMPUTING (ICIVC), 2018, : 821 - 827
  • [48] Moving Target Defense for the CloudControl Game
    Hamasaki, Koji
    Hohjo, Hitoshi
    ADVANCES IN INFORMATION AND COMPUTER SECURITY, IWSEC 2021, 2021, 12835 : 241 - 251
  • [49] A moving target DDoS defense mechanism
    Wang, Huangxin
    Jia, Quan
    Fleck, Dan
    Powell, Walter
    Li, Fei
    Stavrou, Angelos
    COMPUTER COMMUNICATIONS, 2014, 46 : 10 - 21
  • [50] A comparison of moving target defense strategies
    Zhang, Jingzhe
    Wang, Dongxia
    Feng, Xuewei
    2018 IEEE 15TH INTERNATIONAL CONFERENCE ON MOBILE AD HOC AND SENSOR SYSTEMS (MASS), 2018, : 543 - 547