OAK

Time-Based Moving Target Defense Using Bayesian Attack Graph Analysis

Metadata Downloads
Abstract
The moving target defense (MTD) is a proactive cybersecurity defense technique that constantly changes potentially vulnerable points to be attacked, to confuse the attackers, making it difficult for attackers to infer the system configuration and nullify reconnaissance activities to a victim system. We consider an MTD strategy for software-defined networking (SDN) environment where every SDN switch is controlled by a central SDN controller. As the MTD may incur excessive usage of the network/system resources for cybersecurity purposes, we propose to perform the MTD operations adaptively according to the security risk assessment based on a Bayesian attack graph (BAG) analysis. For accurate BAG analysis, we model random and weakest-first attack behaviors and incorporate the derived analytical models into the BAG analysis. Using the BAG analysis result, we formulate a knapsack problem to determine the optimal set of vulnerabilities to be reconfigured under a constraint of SDN reconfiguration overhead. The experiment results prove that the proposed MTD strategy outperforms the full MTD and random MTD counterparts in terms of the maximum/average of attack success probabilities and the number of SDN reconfiguration updates.
Author(s)
Kim HyejinHwang, Eui SeokKim DongseongCho Jin-HeeMoore Terrence J.Nelson Frederica F.Lim Hyuk
Issued Date
2023-04
Type
Article
DOI
10.1109/ACCESS.2023.3269018
URI
https://scholar.gist.ac.kr/handle/local/10264
Publisher
Institute of Electrical and Electronics Engineers Inc.
Citation
IEEE Access, v.11, pp.40511 - 40524
ISSN
2169-3536
Appears in Collections:
Department of Electrical Engineering and Computer Science > 1. Journal Articles
공개 및 라이선스
  • 공개 구분공개
파일 목록

Items in Repository are protected by copyright, with all rights reserved, unless otherwise indicated.