Reasoning about Moving Target Defense in Attack Modeling Formalisms

被引:1
|
作者
Ballot, Gabriel [1 ]
Malvone, Vadim [1 ]
Leneutre, Jean [1 ]
Borde, Etienne [1 ]
机构
[1] Inst Polytech Paris, Telecom Paris, LTCI, Palaiseau, France
来源
PROCEEDINGS OF THE 9TH ACM WORKSHOP ON MOVING TARGET DEFENSE, MTD 2022 | 2022年
关键词
Timed Model checking; Cyber Security; Threat Modeling; Moving Target Defense; FOUNDATIONS;
D O I
10.1145/3560828.3564009
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Since 2009, Moving Target Defense (MTD) has become a new paradigm of defensive mechanism that frequently changes the state of the target system to confuse the attacker. This frequent change is costly and leads to a trade-off between misleading the attacker and disrupting the quality of service. Optimizing the MTD activation frequency is necessary to develop this defense mechanism when facing realistic, multi-step attack scenarios. Attack modeling formalisms based on DAG are prominently used to specify these scenarios. Our contribution is a new DAG-based formalism for MTDs and its translation into a Price Timed Markov Decision Process to find the best activation frequencies against the attacker's time/costoptimal strategies. For the first time, MTD activation frequencies are analyzed in a state-of-the-art DAG-based representation. Moreover, this is the first paper that considers the specificity of MTDs in the automatic analysis of attack modeling formalisms. Finally, we present some experimental results using Uppaal StRatego to demonstrate its applicability and relevance.
引用
收藏
页码:55 / 65
页数:11
相关论文
共 50 条
  • [1] DDoS Attack Isolation using Moving Target Defense
    Department, Kansal
    Dave, Mayank
    2017 IEEE INTERNATIONAL CONFERENCE ON COMPUTING, COMMUNICATION AND AUTOMATION (ICCCA), 2017, : 511 - 514
  • [2] Mitigation of DDoS Attack Using Moving Target Defense in SDN
    Swami, Rochak
    Dave, Mayank
    Ranga, Virender
    WIRELESS PERSONAL COMMUNICATIONS, 2023, 131 (04) : 2429 - 2443
  • [3] Markov Modeling of Moving Target Defense Games
    Maleki, Hoda
    Valizadeh, Saeed
    Koch, William
    Bestavros, Azer
    van Dijk, Marten
    MTD'16: PROCEEDINGS OF THE 2016 ACM WORKSHOP ON MOVING TARGET DEFENSE, 2016, : 81 - 92
  • [4] Mitigation of DDoS Attack Using Moving Target Defense in SDN
    Rochak Swami
    Mayank Dave
    Virender Ranga
    Wireless Personal Communications, 2023, 131 : 2429 - 2443
  • [5] Evaluating Deception and Moving Target Defense with Network Attack Simulation
    Reti, Daniel
    Elzer, Karina
    Fraunholz, Daniel
    Schneider, Daniel
    Schotten, Hans Dieter
    PROCEEDINGS OF THE 9TH ACM WORKSHOP ON MOVING TARGET DEFENSE, MTD 2022, 2022, : 45 - 53
  • [6] A Defense Method Based on Moving Target Defense for New Power System APT Attack
    Li, Ruotong
    Li, Yuancheng
    International Journal of Network Security, 2023, 25 (04) : 587 - 594
  • [7] Defending Blind DDoS Attack on SDN Based on Moving Target Defense
    Ma, Duohe
    Xu, Zhen
    Lin, Dongdai
    INTERNATIONAL CONFERENCE ON SECURITY AND PRIVACY IN COMMUNICATION NETWORKS, SECURECOMM 2014, PT I, 2015, 152 : 463 - 480
  • [8] ShuffleCAN: Enabling Moving Target Defense for Attack Mitigation on Automotive CAN
    Qian, Huiping
    Han, Hao
    Zhu, Xiaojun
    Xu, Fengyuan
    2023 19TH INTERNATIONAL CONFERENCE ON MOBILITY, SENSING AND NETWORKING, MSN 2023, 2023, : 351 - 358
  • [9] An Optimal Design of a Moving Target Defense for Attack Detection in Control Systems
    Griffioen, Paul
    Weerakkody, Sean
    Sinopoli, Bruno
    2019 AMERICAN CONTROL CONFERENCE (ACC), 2019, : 4527 - 4534
  • [10] Proactive attack detection scheme based on watermarking and moving target defense
    Liu, Hao
    Zhang, Yewei
    Li, Yuzhe
    Niu, Ben
    AUTOMATICA, 2023, 155