Performance and Security Evaluation of a Moving Target Defense Based on a Software-Defined Networking Environment

被引:1
|
作者
Kim, Minjune [1 ]
Cho, Jin-Hee [2 ]
Lim, Hyuk [3 ]
Moore, Terrence J. [4 ]
Nelson, Frederica F. [4 ]
Kim, Dan Dongseong [1 ]
机构
[1] Univ Queensland, Brisbane, Qld, Australia
[2] Virginia Tech, Blacksburg, VA USA
[3] Korea Inst Energy Technol KENTECH, Naju, South Korea
[4] US Army Res Lab, Adelphi, MD USA
关键词
Performance evaluation; security evaluation; moving target defense; Apache web service; Denial-of-Service attack; dictionary attack; SQL injection attack;
D O I
10.1109/PRDC55274.2022.00026
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
As cyberattacks continuously threaten conventional defense techniques, Moving Target Defense (MTD) has emerged as a promising countermeasure to defend a system against them by dynamically changing attack surfaces of the system. MTD provides the system a state-of-art security mechanism that increases the attack cost or complexity of the system aiming for reducing vulnerabilities exposed to potential attackers. However, the notion of the proactive and dynamic systems adopting MTD services causes a substantial trade-off between system performance and security effectiveness, compared to conventional defense strategies. The MTD tactics accordingly result in performance degradation (e.g., interruptions of service availability) as one of the drawbacks caused by continuous mutations of the system configuration. Therefore, it is crucial to validate not only the security benefits against system threats but also quality-of-service (QoS) for clients when an MTDenabled system proactively continues to mutate attack surfaces. This paper contributes to (i) developing new security metrics; (ii) measuring both the performance degradation and security effectiveness against potential real attacks (i.e., scanning, HTTP flood, dictionary, and SQL injection attack); and (iii) comparing the proposed job management strategies (i.e., drop and switchover) from a performance and security perspective in a physical SDN testbed.
引用
收藏
页码:119 / 129
页数:11
相关论文
共 50 条
  • [1] Look Again, Neo: A Software-Defined Networking Moving Target Defense
    Mayer, Samuel
    Reith, Mark
    Mullins, Barry
    [J]. PROCEEDINGS OF THE 13TH INTERNATIONAL CONFERENCE ON CYBER WARFARE AND SECURITY (ICCWS 2018), 2018, : 602 - 610
  • [2] Frequency-Minimal Moving Target Defense using Software-Defined Networking
    Debroy, Saptarshi
    Calyam, Prasad
    Nguyen, Minh
    Stage, Allen
    Georgiev, Vladimir
    [J]. 2016 INTERNATIONAL CONFERENCE ON COMPUTING, NETWORKING AND COMMUNICATIONS (ICNC), 2016,
  • [3] Dynamic Security Metrics for Software-Defined Network-based Moving Target Defense
    Sharma, Dilli P.
    Enoch, Simon Yusuf
    Cho, Jin-Hee
    Moore, Terrence J.
    Nelson, Frederica F.
    Lim, Hyuk
    Kim, Dong Seong
    [J]. JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2020, 170
  • [4] Towards Dynamically Shifting Cyber Terrain With Software-Defined Networking and Moving Target Defense
    Larkin, Robert
    Jensen, Steven
    Koranek, Daniel
    Mullins, Barry
    Reith, Mark
    [J]. PROCEEDINGS OF THE 16TH INTERNATIONAL CONFERENCE ON CYBER WARFARE AND SECURITY (ICCWS 2021), 2021, : 535 - 540
  • [5] Performability Analysis of Services in a Software-Defined Networking Adopting Time-Based Moving Target Defense
    Mendonca, Julio
    Cho, Jin-Hee
    Moore, Terrence J.
    Nelson, Frederica F.
    Lim, Hyuk
    Zimmermann, Armin
    Kim, Dong Seong
    [J]. PROCEEDINGS OF THE 35TH ANNUAL ACM SYMPOSIUM ON APPLIED COMPUTING (SAC'20), 2020, : 1180 - 1189
  • [6] POSTER: Toward Intelligent Cyber Attacks for Moving Target Defense Techniques in Software-Defined Networking
    Moghaddam, Tina
    Yang, Guowei
    Thapa, Chandra
    Camtepe, Seyit
    Kim, Dan Dongseong
    [J]. PROCEEDINGS OF THE 2023 ACM ASIA CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, ASIA CCS 2023, 2023, : 1022 - 1024
  • [7] Performance Evaluation of the Controller in Software-Defined Networking
    Rout, Suchismita
    Patra, Sudhansu Shekhar
    Sahoo, Bibhudatta
    [J]. COMPUTATIONAL INTELLIGENCE IN DATA MINING, CIDM 2016, 2017, 556 : 543 - 551
  • [8] Attack Graph-Based Moving Target Defense in Software-Defined Networks
    Yoon, Seunghyun
    Cho, Jin-Hee
    Kim, Dong Seong
    Moore, Terrence J.
    Free-Nelson, Frederica
    Lim, Hyuk
    [J]. IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2020, 17 (03): : 1653 - 1668
  • [9] Design and Performance Analysis of Software Defined Networking based Web Services Adopting Moving Target Defense
    Kim, Dong Seong
    Kim, Minjune
    Cho, Jin-Hee
    Lim, Hyuk
    Moore, Terrence J.
    Nelson, Frederica F.
    [J]. 2020 50TH ANNUAL IEEE-IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS-SUPPLEMENTAL VOLUME (DSN-S), 2020, : 43 - 44
  • [10] A Framework for Security Services based on Software-Defined Networking
    Jeong, Jaehoon
    Seo, Jihyeok
    Cho, Geumhwan
    Kim, Hyoungshick
    Park, Jung-Soo
    [J]. 2015 IEEE 29TH INTERNATIONAL CONFERENCE ON ADVANCED INFORMATION NETWORKING AND APPLICATIONS WORKSHOPS WAINA 2015, 2015, : 150 - 153