FRVM: Flexible Random Virtual IP Multiplexing in Software-Defined Networks

被引:42
|
作者
Sharma, Dilli P. [1 ]
Kim, Dong Seong [1 ]
Yoon, Seunghyun [2 ]
Lim, Hyuk [2 ]
Cho, Jin-Hee [3 ]
Moore, Terrence J. [3 ]
机构
[1] Univ Canterbury, Christchurch, New Zealand
[2] Gwangju Inst Sci & Technol, Gwangju, South Korea
[3] Army Res Lab, Adelphi, MD USA
关键词
Network address shuffling; IP multiplexing; moving target defense; scanning attacks; attack success probability; software-defined networks; PORT;
D O I
10.1109/TrustCom/BigDataSE.2018.00088
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Network address shuffling is one of moving target defense (MTD) techniques that can invalidate the address information attackers have collected based on the current network IP configuration. We propose a software-defined networking-based MTD technique called Flexible Random Virtual IP Multiplexing, namely FRVM, which aims to defend against network reconnaissance and scanning attacks. FRVM enables a host machine to have multiple, random, time-varying virtual IP addresses, which are multiplexed to a real IP address of the host. Multiplexing or de-multiplexing event dynamically remaps all the virtual network addresses of the hosts. Therefore, at the end of a multiplexing event, FRVM aims to make the attackers lose any knowledge gained through the reconnaissance and to disturb their scanning strategy. In this work, we analyze and evaluate our proposed FRVM in terms of the attack success probability under scanning attacks and target host discovery attacks.
引用
收藏
页码:579 / 587
页数:9
相关论文
共 50 条
  • [21] Random Access and Virtual Resource Allocation in Software-Defined Cellular Networks With Machine-to-Machine Communications
    Li, Meng
    Yu, F. Richard
    Si, Pengbo
    Sun, Enchang
    Zhang, Yanhua
    Yao, Haipeng
    [J]. IEEE TRANSACTIONS ON VEHICULAR TECHNOLOGY, 2017, 66 (07) : 6399 - 6414
  • [22] Supporting Dynamic Bandwidth Adjustment Based on Virtual Transport Link in Software-Defined IP Over Optical Networks
    Zhou, Yu
    Ramamurthy, Byrav
    Guo, Bingli
    Huang, Shanguo
    [J]. JOURNAL OF OPTICAL COMMUNICATIONS AND NETWORKING, 2018, 10 (03) : 125 - 137
  • [23] Languages for Software-Defined Networks
    Foster, Nate
    Guha, Arjun
    Reitblatt, Mark
    Story, Alec
    Freedman, Michael J.
    Katta, Naga Praveen
    Monsanto, Christopher
    Reich, Joshua
    Rexford, Jennifer
    Schlesinger, Cole
    Walker, David
    Harrison, Major Robert
    [J]. IEEE COMMUNICATIONS MAGAZINE, 2013, 51 (02) : 128 - 134
  • [24] On the Security of Software-Defined Networks
    Prasad, Abhinandan S.
    Koll, David
    Fu, Xiaoming
    [J]. 2015 FOURTH EUROPEAN WORKSHOP ON SOFTWARE DEFINED NETWORKS - EWSDN 2015, 2015, : 105 - 106
  • [25] Software-Defined Access Networks
    Elbers, Joerg-Peter
    Grobe, Klaus
    Magee, Anthony
    [J]. 2014 EUROPEAN CONFERENCE ON OPTICAL COMMUNICATION (ECOC), 2014,
  • [26] Abstractions for Software-Defined Networks
    Casado, Martin
    Foster, Nate
    Guha, Arjun
    [J]. COMMUNICATIONS OF THE ACM, 2014, 57 (10) : 86 - 95
  • [27] On the Fingerprinting of Software-Defined Networks
    Cui, Heng
    Karame, Ghassan O.
    Klaedtke, Felix
    Bifulco, Roberto
    [J]. IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2016, 11 (10) : 2160 - 2173
  • [28] Fingerprinting Software-defined Networks
    Bifulco, Roberto
    Cui, Heng
    Karame, Ghassan O.
    Klaedtke, Felix
    [J]. 2015 IEEE 23RD INTERNATIONAL CONFERENCE ON NETWORK PROTOCOLS (ICNP), 2015, : 453 - 459
  • [29] Software-Defined Access Networks
    Kerpez, Kenneth J.
    Cioffi, John M.
    Ginis, George
    Goldburg, Marc
    Galli, Stefano
    Silverman, Peter
    [J]. IEEE COMMUNICATIONS MAGAZINE, 2014, 52 (09) : 152 - 159
  • [30] Future Scenarios for Software-Defined Metro and Access Networks and Software-Defined Photonics
    Muciaccia, Tommaso
    Passaro, Vittorio M. N.
    [J]. PHOTONICS, 2017, 4 (01)