...
首页> 外文期刊>International Journal of Networking and Computing >Analyzing the Effect of Moving Target Defense for a Web System
【24h】

Analyzing the Effect of Moving Target Defense for a Web System

机译:分析移动目标防御对Web系统的影响

获取原文
           

摘要

Moving target defense (MTD) is a feasible idea for reducing the ratio of successful attacks by altering or diversifying the attributes or parameters of a protected system. As a result of applying MTD techniques to a system, an attacker would have more difficulties in launching attacks. Although several MTD techniques have been proposed for different types of attack, estimating the effectiveness of combining these MTDs remains a challenge. With the aim of setting up a method for evaluating MTDs, we first propose a model composed of two MTD diversification techniques to compare an attack success ratio between theoretical and experimental probability. To validate the proposed model, we conducted an experiment involving an actual attack and then analyzed how our MTD model can adequately estimate a binary-code injection attack. Results show that the rate of attack success is 100% when MTD diversification is not implemented, while the rate is reduced depending on how many variants can be diversified in a target system. Our method is an important first step toward establishing a method for evaluating MTDs, as well as predicting an MTD’s defensive abilities.
机译:移动目标防御(MTD)是通过更改或分散受保护系统的属性或参数来降低成功攻击率的可行想法。将MTD技术应用于系统的结果是,攻击者在发起攻击时会遇到更多困难。尽管已经针对不同类型的攻击提出了几种MTD技术,但是估计组合这些MTD的有效性仍然是一个挑战。为了建立一种评估MTD的方法,我们首先提出一个由两种MTD多样化技术组成的模型,以比较理论概率和实验概率之间的攻击成功率。为了验证所提出的模型,我们进行了涉及实际攻击的实验,然后分析了我们的MTD模型如何充分估计二进制代码注入攻击。结果表明,如果不实施MTD多样化,则攻击成功率为100%,而降低的成功率取决于目标系统中可以多样化的变体数量。我们的方法是建立评估MTD以及预测MTD防御能力的重要的第一步。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号