FRVM: Flexible Random Virtual IP Multiplexing in Software-Defined Networks

被引:42
|
作者
Sharma, Dilli P. [1 ]
Kim, Dong Seong [1 ]
Yoon, Seunghyun [2 ]
Lim, Hyuk [2 ]
Cho, Jin-Hee [3 ]
Moore, Terrence J. [3 ]
机构
[1] Univ Canterbury, Christchurch, New Zealand
[2] Gwangju Inst Sci & Technol, Gwangju, South Korea
[3] Army Res Lab, Adelphi, MD USA
关键词
Network address shuffling; IP multiplexing; moving target defense; scanning attacks; attack success probability; software-defined networks; PORT;
D O I
10.1109/TrustCom/BigDataSE.2018.00088
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Network address shuffling is one of moving target defense (MTD) techniques that can invalidate the address information attackers have collected based on the current network IP configuration. We propose a software-defined networking-based MTD technique called Flexible Random Virtual IP Multiplexing, namely FRVM, which aims to defend against network reconnaissance and scanning attacks. FRVM enables a host machine to have multiple, random, time-varying virtual IP addresses, which are multiplexed to a real IP address of the host. Multiplexing or de-multiplexing event dynamically remaps all the virtual network addresses of the hosts. Therefore, at the end of a multiplexing event, FRVM aims to make the attackers lose any knowledge gained through the reconnaissance and to disturb their scanning strategy. In this work, we analyze and evaluate our proposed FRVM in terms of the attack success probability under scanning attacks and target host discovery attacks.
引用
收藏
页码:579 / 587
页数:9
相关论文
共 50 条
  • [1] Random Host and Service Multiplexing for Moving Target Defense in Software-Defined Networks
    Sharma, Dilli P.
    Cho, Jin-Hee
    Moore, Terrence J.
    Nelson, Frederica F.
    Lim, Hyuk
    Kim, Dong Seong
    [J]. ICC 2019 - 2019 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2019,
  • [2] Software-Defined Mobility Support in IP Networks
    Wang, You
    Bi, Jun
    [J]. COMPUTER JOURNAL, 2016, 59 (02): : 159 - 177
  • [3] Software-Defined Multiplexing Codes
    Huang, Scott C. -H.
    Wu, Hsiao-Chun
    [J]. 2015 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2015,
  • [4] Virtual Network Embedding in Software-Defined Networks
    Bays, Leonardo Richter
    Gaspary, Luciano Paschoal
    Ahmed, Reaz
    Boutaba, Raouf
    [J]. NOMS 2016 - 2016 IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM, 2016, : 10 - 18
  • [5] Software-Defined Congestion Control Algorithm for IP Networks
    Hu, Yao
    Peng, Ting
    Zhang, Lianming
    [J]. SCIENTIFIC PROGRAMMING, 2017, 2017
  • [6] Embedding Virtual Multicast Trees in Software-Defined Networks
    Guler, Evrim
    Zheng, Danyang
    Luo, Guangchun
    Tian, Ling
    Cao, Xiaojun
    [J]. 2017 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2017,
  • [7] Rethinking Virtual Private Networks in the Software-Defined Era
    Lospoto, Gabriele
    Rimondini, Massimo
    Vignoli, Benedetto Gabriele
    Di Battista, Giuseppe
    [J]. PROCEEDINGS OF THE 2015 IFIP/IEEE INTERNATIONAL SYMPOSIUM ON INTEGRATED NETWORK MANAGEMENT (IM), 2015, : 379 - 387
  • [8] Virtual Machine Migration Planning in Software-Defined Networks
    Wang, Huandong
    Li, Yong
    Zhang, Ying
    Jin, Depeng
    [J]. 2015 IEEE CONFERENCE ON COMPUTER COMMUNICATIONS (INFOCOM), 2015,
  • [9] Virtual network embedding in software-defined hybrid networks
    Ran X.
    Wendong W.
    Xiangyang G.
    Xirong Q.
    [J]. Journal of China Universities of Posts and Telecommunications, 2018, 25 (04): : 75 - 85
  • [10] Virtual network embedding in software-defined hybrid networks
    Xu Ran
    Wang Wendong
    Gong Xiangyang
    Que Xirong
    [J]. The Journal of China Universities of Posts and Telecommunications, 2018, 25 (04) : 75 - 85