MPD: Moving Target Defense Through Communication Protocol Dialects

نویسندگان

چکیده

Communication protocol security is among the most significant challenges of Internet Things (IoT) due to wide variety hardware and software technologies involved. Moving target defense (MTD) has been adopted as an innovative strategy solve this problem by dynamically changing system properties configurations obfuscate attack surface. Nevertheless, existing work MTD primarily focuses on lower-level (e.g., IP addresses or port numbers), only a limited number variations can be generated based these properties. In paper, we propose new approach through communication dialects (MPD) - which customizes into various leverages them create moving defense. Specifically, MPD harnesses dialect generating function then mapping select one specific for each packet during communication. To keep different network entities in synchronization, also design self-synchronization mechanism utilizing pseudo-random generator with input pre-shared secret key previously sent packets. We implement prototype evaluate its feasibility standard (i.e., File Transfer Protocol) internet things Message Queuing Telemetry Transport). The results indicate that effectively address attacks including denial service malicious modifications negligible overhead.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Symbiotes and defensive Mutualism: Moving Target Defense

If we wish to break the continual cycle of patching and replacing our core monoculture systems to defend against attacker evasion tactics, we must redesign the way systems are deployed so that the attacker can no longer glean the information about one system that allows attacking any other like system. Hence, a new poly-culture architecture that provides complete uniqueness for each distinct de...

متن کامل

A moving target DDoS defense mechanism

In this paper, we introduce a moving target defense mechanism that defends authenticated clients against Internet service DDoS attacks. Our mechanism employs a group of dynamic, hidden proxies to relay traffic between authenticated clients and servers. By continuously replacing attacked proxies with backup proxies and reassigning (shuffling) the attacked clients onto the new proxies, innocent c...

متن کامل

Random Host Mutation for Moving Target Defense

Exploiting static configuration of networks and hosts has always been a great advantage for design and launching of decisive attacks. Network reconnaissance of IP addresses and ports is prerequisite to many host and network attacks. At the same time, knowing IP addresses is required for service reachability in IP networks, which makes complete concealment of IP address for servers infeasible. I...

متن کامل

A Framework for Moving Target Defense Quantification

Moving Target Defense (MTD) has emerged as a game changer in the security landscape, as it can create asymmetric uncertainty favoring the defender. Despite the significant work done in this area and the many different techniques that have been proposed, MTD has not yet gained widespread adoption due to several limitations. Specifically, interactions between multiple techniques have not been stu...

متن کامل

Evaluating Moving Target Defense with PLADD

This project evaluates the effectiveness of moving target defense (MTD) techniques using a new game we have designed, called PLADD, inspired by the game FlipIt [28]. PLADD extends FlipIt by incorporating what we believe are key MTD concepts. We have analyzed PLADD and proven the existence of a defender strategy that pushes a rational attacker out of the game, demonstrated how limited the strate...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

ژورنال

عنوان ژورنال: Lecture Notes in Computer Science

سال: 2021

ISSN: ['1611-3349', '0302-9743']

DOI: https://doi.org/10.1007/978-3-030-90019-9_6