A Moving-target Defense Strategy for Cloud-based Services with Heterogeneous and Dynamic Attack Surfaces

被引:0
|
作者
Peng, Wei [1 ]
Li, Feng [2 ]
Huang, Chin-Tser [3 ]
Zou, Xukai [1 ]
机构
[1] Indiana Univ Purdue Univ, Dept Comp & Informat Sci, Indianapolis, IN 46202 USA
[2] Indiana Univ Purdue Univ, Dept Comp Informat & Graph Technol, Indianapolis, IN 46202 USA
[3] Univ S Carolina, Dept Comp Sci & Engn, Columbia, SC 29208 USA
来源
2014 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC) | 2014年
关键词
moving-target defense; risk modeling; probabilistic algorithm; simulation;
D O I
暂无
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
Due to deep automation, the configuration of many Cloud infrastructures is static and homogeneous, which, while easing administration, significantly decreases a potential attacker's uncertainty on a deployed Cloud-based service and hence increases the chance of the service being compromised. Moving-target defense (MTD) is a promising solution to the configuration staticity and homogeneity problem. This paper presents our findings on whether and to what extent MTD is effective in protecting a Cloud-based service with heterogeneous and dynamic attack surfaces-these attributes, which match the reality of current Cloud infrastructures, have not been investigated together in previous works on MTD in general network settings. We 1) formulate a Cloud-based service security model that incorporates Cloud-specific features such as VM migration/snapshotting and the diversity/compatibility of migration, 2) consider the accumulative effect of the attacker's intelligence on the target service's attack surface, 3) model the heterogeneity and dynamics of the service's attack surfaces, as defined by the (dynamic) probability of the service being compromised, as an S-shaped generalized logistic function, and 4) propose a probabilistic MTD service deployment strategy that exploits the dynamics and heterogeneity of attack surfaces for protecting the service against attackers. Through simulation, we identify the conditions and extent of the proposed MTD strategy's effectiveness in protecting Cloud-based services. Namely, 1) MTD is more effective when the service deployment is dense in the replacement pool and/or when the attack is strong, and 2) attack-surface heterogeneity-and-dynamics awareness helps in improving MTD's effectiveness.
引用
收藏
页码:804 / 809
页数:6
相关论文
共 50 条
  • [1] MTD CBITS: Moving Target Defense for Cloud-Based IT Systems
    Bardas, Alexandru G.
    Sundaramurthy, Sathya Chandran
    Ou, Xinming
    DeLoach, Scott A.
    COMPUTER SECURITY - ESORICS 2017, PT I, 2018, 10492 : 167 - 186
  • [2] MIGRATE: Towards a Lightweight Moving-target Defense against Cloud Side-Channels
    Azab, Mohamed
    Eltoweissy, Mohamed
    2016 IEEE SYMPOSIUM ON SECURITY AND PRIVACY WORKSHOPS (SPW 2016), 2016, : 96 - 103
  • [3] Survey on Attack Surface Dynamic Transfer Technology Based on Moving Target Defense
    Zhou Y.-Y.
    Cheng G.
    Guo C.-S.
    Dai M.
    Ruan Jian Xue Bao/Journal of Software, 2018, 29 (09): : 2799 - 2820
  • [4] Diversity-based Moving-target Defense for Secure Wireless Vehicular Communications
    Ghourab, Esraa M.
    Samir, Effat
    Azab, Mohamed
    Eltoweissy, Mohamed
    2018 IEEE SYMPOSIUM ON SECURITY AND PRIVACY WORKSHOPS (SPW 2018), 2018, : 287 - 292
  • [5] Anonymous blockchain Based Routing For Moving-target Defense Across Federated Clouds
    Magdy, Yousra
    Kashkoush, Mona S.
    Azab, Mohamed
    Rizk, Mohamed R. M.
    2020 IEEE 21ST INTERNATIONAL CONFERENCE ON HIGH PERFORMANCE SWITCHING AND ROUTING (IEEE HPSR), 2020,
  • [6] Toward deceiving the intrusion attacks in containerized cloud environment using virtual private cloud-based moving target defense
    Hyder, Muhammad Faraz
    Ahmed, Waqas
    Ahmed, Maaz
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2023, 35 (05):
  • [7] SD-MTD: Software-Defined Moving-Target Defense for Cloud-System Obfuscation
    Kang, Ki-Wan
    Seo, Jung Taek
    Baek, Sung Hoon
    Kim, Chul Woo
    Park, Ki-Woong
    KSII TRANSACTIONS ON INTERNET AND INFORMATION SYSTEMS, 2022, 16 (03): : 1063 - 1075
  • [8] Dynamic Request Redirection and Resource Provisioning for Cloud-Based Video Services under Heterogeneous Environment
    Xiao, Wenhua
    Bao, Weidong
    Zhu, Xiaomin
    Wang, Chen
    Chen, Lidong
    Yang, Laurence T.
    IEEE TRANSACTIONS ON PARALLEL AND DISTRIBUTED SYSTEMS, 2016, 27 (07) : 1954 - 1967
  • [9] A Cloud-Based Dynamic Random Software Testing Strategy
    Pei, Hanyu
    Yin, Beibei
    Xie, Min
    Cai, Kai-Yuan
    2017 IEEE INTERNATIONAL CONFERENCE ON INDUSTRIAL ENGINEERING AND ENGINEERING MANAGEMENT (IEEM), 2017, : 509 - 513
  • [10] CLOUD-BASED CALCULUS FOR BUSINESS: MOVING FROM STATIC TO DYNAMIC
    Tasic, B.
    EDULEARN18: 10TH INTERNATIONAL CONFERENCE ON EDUCATION AND NEW LEARNING TECHNOLOGIES, 2018, : 8794 - 8798