首页> 外文期刊>IEEE transactions on network and service management >Attack Graph-Based Moving Target Defense in Software-Defined Networks
【24h】

Attack Graph-Based Moving Target Defense in Software-Defined Networks

机译:在软件定义的网络中攻击基于图形的移动目标防御

获取原文
获取原文并翻译 | 示例
           

摘要

Moving target defense (MTD) has emerged as a proactive defense mechanism aiming to thwart a potential attacker. The key underlying idea of MTD is to increase uncertainty and confusion for attackers by changing the attack surface (i.e., system or network configurations) that can invalidate the intelligence collected by the attackers and interrupt attack execution; ultimately leading to attack failure. Recently, the significant advance of software-defined networking (SDN) technology has enabled several complex system operations to be highly flexible and robust; particularly in terms of programmability and controllability with the help of SDN controllers. Accordingly, many security operations have utilized this capability to be optimally deployed in a complex network using the SDN functionalities. In this paper, by leveraging the advanced SDN technology, we developed an attack graph-based MTD technique that shuffles a host's network configurations (e.g., MAC/IP/port addresses) based on its criticality, which is highly exploitable by attackers when the host is on the attack path(s). To this end, we developed a hierarchical attack graph model that provides a network's vulnerability and network topology, which can be utilized for the MTD shuffling decisions in selecting highly exploitable hosts in a given network, and determining the frequency of shuffling the hosts' network configurations. The MTD shuffling with a high priority on more exploitable, critical hosts contributes to providing adaptive, proactive, and affordable defense services aiming to minimize attack success probability with minimum MTD cost. We validated the out performance of the proposed MTD in attack success probability and MTD cost via both simulation and real SDN testbed experiments.
机译:移动目标防御(MTD)被出现为旨在阻止潜在攻击者的主动防御机制。 MTD的关键潜在思想是通过改变攻击表面(即系统或网络配置)来增加攻击者的不确定性和混淆,这可以使攻击者收集的智能和中断攻击执行无效;最终导致攻击失败。最近,软件定义网络(SDN)技术的显着进展使多个复杂的系统操作能够具有高度灵活和强大的;特别是在SDN控制器的帮助下,在可编程性和可控性方面。因此,许多安全操作已经利用了使用SDN功能在复杂网络中最佳地部署的这种能力。在本文中,通过利用先进的SDN技术,我们开发了一种基于攻击图的MTD技术,基于其关键性将主机的网络配置(例如,MAC / IP /端口地址)减速,这是攻击者在主机时高度可利用在攻击路径上。为此,我们开发了一个分层攻击图模型,提供了一种网络的漏洞和网络拓扑,可以用于MTD洗机决策,在给定网络中选择高度可利用的主机,并确定Shuffling网络配置的频率。 MTD Shuffling以更高的优先级提出更高的关键主机,有助于提供适应性,主动和实惠的防御服务,旨在以最低的MTD成本最大限度地减少攻击成功概率。我们通过仿真和真实SDN测试实验验证了攻击成功概率和MTD成本的拟议MTD的表现。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号