Smart collaborative distribution for privacy enhancement in moving target defense

被引:81
作者
Song, Fei [1 ]
Zhou, Yu-Tong [2 ]
Wang, Yu [3 ]
Zhao, Tian-Ming [1 ]
You, Ilsun [4 ]
Zhang, Hong-Ke [1 ]
机构
[1] Beijing Jiaotong Univ, Sch Elect & Informat Engn, Beijing, Peoples R China
[2] Univ Int Business & Econ, Inst Educ & Econ Res, Beijing, Peoples R China
[3] Univ Int Business & Econ, Sch Int Trade & Econ, Beijing, Peoples R China
[4] Soonchunhyang Univ, Dept Informat Secur Engn, Asan, South Korea
关键词
Moving target defense; Smart collaboration; Network privacy; DNS attacks; Port hopping; DNS;
D O I
10.1016/j.ins.2018.06.002
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The Moving Target Defense (MTD) has been widely discussed in many communities to upgrade the network reliability, survivability, dependability, etc. However, utilizing MTD in privacy protection still needs more investigations. In this paper, we propose a smart collaborative distribution scheme to enhance the privacy based on MTD guidelines. A target application scenario is the Domain Name System (DNS) that is experiencing serious and complex privacy issues. The preliminary and potential risks are firstly analyzed based on DNS attack approaches, DNS server locations and the vulnerability of user privacy. Then, the details of our scheme are illustrated through port number assignment patterns, main procedures of dynamic port hopping and the implementation method. To quantitatively evaluate the performance, an analytical model was established from theoretical perspectives. The relationships between multiple parameters and overall system capacity are explored as well. The validation results demonstrate that the smart collaborative distribution is able to improve the privacy without affecting the basic DNS functionality. (C) 2018 Elsevier Inc. All rights reserved.
引用
收藏
页码:593 / 606
页数:14
相关论文
共 50 条
[1]  
Adili Mohammad Taghi, 2017, 2017 IFIP/IEEE Symposium on Integrated Network and Service Management (IM), P98, DOI 10.23919/INM.2017.7987269
[2]  
[Anonymous], 2015, P 4 ANN ACM C RES IN
[3]  
Arends Roy, 2005, Rfc 4035: protocol modifications for the dns security extensions
[4]   Mitigating Crossfire Attacks using SDN-based Moving Target Defense [J].
Aydeger, Abdullah ;
Saputro, Nico ;
Akkaya, Kemal ;
Rahman, Mohammad .
2016 IEEE 41ST CONFERENCE ON LOCAL COMPUTER NETWORKS (LCN), 2016, :627-630
[5]   MIGRATE: Towards a Lightweight Moving-target Defense against Cloud Side-Channels [J].
Azab, Mohamed ;
Eltoweissy, Mohamed .
2016 IEEE SYMPOSIUM ON SECURITY AND PRIVACY WORKSHOPS (SPW 2016), 2016, :96-103
[6]   Detection and Forensics of Domains Hijacking [J].
Borgwart, Andreas ;
Boukoros, Spyros ;
Shulman, Haya ;
van Rooyen, Carel ;
Waidner, Michael .
2015 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2015,
[7]  
Callahan T, 2013, ACM SIGCOMM COMP COM, V43, P8
[8]   Moving-Target Defenses for Computer Networks [J].
Carvalho, Marco ;
Ford, Richard .
IEEE SECURITY & PRIVACY, 2014, 12 (02) :73-76
[9]  
Chitpranee Ruetee, 2013, P 9 AS INT ENG C AIN, P9
[10]  
Cotton M., 2011, 6335 RFC INT ENG TAS