【24h】

A Framework for Moving Target Defense Quantification

机译:移动目标防御量化的框架

获取原文

摘要

Moving Target Defense (MTD) has emerged as a game changer in the security landscape, as it can create asymmetric uncertainty favoring the defender. Despite the significant work done in this area and the many different techniques that have been proposed, MTD has not yet gained widespread adoption due to several limitations. Specifically, interactions between multiple techniques have not been studied yet and a unified framework for quantifying and comparing very diverse techniques is still lacking. To overcome these limitations, we propose a framework to model how different MTD techniques can affect the information an attacker needs to exploit a system's vulnerabilities, so as to introduce uncertainty and reduce the likelihood of successful attacks. We illustrate how this framework can be used to compare two sets of MTDs, and to select an optimal set of MTDs that maximize security within a given budget. Experimental results show that our approach is effective.
机译:移动目标防御(MTD)已成为安全景观中的游戏更换器,因为它可以创造不对称的不确定因子,偏好了防御者。尽管在该领域做出了重大工作和所提出的许多不同技术,但MTD由于几个限制而尚未获得广泛的采用。具体地,尚未研究多种技术与用于量化和比较非常多样化的技术的统一框架之间的相互作用仍然缺乏。为了克服这些限制,我们提出了一个框架来模拟不同的MTD技术如何影响攻击者需要利用系统的漏洞的信息,以便引入不确定性并降低成功攻击的可能性。我们说明了该框架如何用于比较两组MTD,并选择最佳的MTD集,可在给定预算中最大化安全性。实验结果表明,我们的方法是有效的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号