Experimental evaluation of the IP address space randomisation (IASR) technique and its disruption to selected network services

نویسنده

  • Maxwell Dondo
چکیده

In recent years, some computer network defence (CND) researchers and experts have been suggesting the use of moving target defence (MTD) as a proactive cyber security approach. MTD is a set of network defence techniques such as randomisation, deception, etc., that significantly increases the attacker’s work effort. One randomisation technique, called internet protocol (IP) address space randomisation (IASR), periodically or aperiodically makes random changes to the network‘s IP addresses. This makes it harder for attackers to achieve their goals. However, despite its security benefits, this defence technique disrupts the functioning of some network services. It is therefore important to understand the level of disruption that comes with the technique. In this work, we experimentally evaluate IASR and its disruptive effects on selected network services. Using virtual machines (VMs), we carried out this experiment by setting up a typical computer network that supports selected network services, namely ping, mail, web, and streaming video. We transformed a typical zoned computer network into a flat network and implemented IASR on it. Then, we executed the four selected network services during IASR and made observations on how disruptive the technology could be on these services. The results of our experimental evaluation show variations in performance degradation in some of the selected services when hosts’ IP addresses are changed during IASR, suggesting the need for IASR-aware services if this technology is to be effectively adopted for CND. Significance for defence and security This report was a deliverable for the Advanced Computer Network Operations (CNO) Tools and Techniques (ACTT) project, whose objective was to study advanced CNO tools and techniques for computer network defence. The experimental work to evaluate the internet protocol (IP) address space randomisation (IASR) technique and its disruptive effects on services in an operational network, partially shows what to expect if such technology is considered for network defence. If network planners and defenders consider IASR as a network defence technique, degradation in service performance that comes with it should be taken into consideration. DRDC-RDDC-2014-R146 i

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

A High Performance Parallel IP Lookup Technique Using Distributed Memory Organization and ISCB-Tree Data Structure

The IP Lookup Process is a key bottleneck in routing due to the increase in routing table size, increasing traıc and migration to IPv6 addresses. The IP address lookup involves computation of the Longest Prefix Matching (LPM), which existing solutions such as BSD Radix Tries, scale poorly when traıc in the router increases or when employed for IPv6 address lookups. In this paper, we describe a ...

متن کامل

A High Performance Parallel IP Lookup Technique Using Distributed Memory Organization and ISCB-Tree Data Structure

The IP Lookup Process is a key bottleneck in routing due to the increase in routing table size, increasing traıc and migration to IPv6 addresses. The IP address lookup involves computation of the Longest Prefix Matching (LPM), which existing solutions such as BSD Radix Tries, scale poorly when traıc in the router increases or when employed for IPv6 address lookups. In this paper, we describe a ...

متن کامل

A Robust Competitive Global Supply Chain Network Design under Disruption: The Case of Medical Device Industry

In this study, an optimization model is proposed to design a Global Supply Chain (GSC) for a medical device manufacturer under disruption in the presence of pre-existing competitors and price inelasticity of demand. Therefore, static competition between the distributors’ facilities to more efficiently gain a further share in market of Economic Cooperation Organization trade agreement (ECOTA) is...

متن کامل

Improve Replica Placement in Content Distribution Networks with Hybrid Technique

The increased using of the Internet and its accelerated growth leads to reduced network bandwidth and the capacity of servers; therefore, the quality of Internet services is unacceptable for users while the efficient and effective delivery of content on the web has an important role to play in improving performance. Content distribution networks were introduced to address this issue. Replicatin...

متن کامل

Positioning of Industries in Cyberspace Evaluation of Web Sites Using Correspondence Analysis

  In today’s extremely competitive markets it is crucial for companies to strategically position their brands, products and services relative to their competitors. With the emerging trend in internationalization of companies especially SME’s and the growing use of the Internet with this regard, great amount of attention has been turned to effective involvement of the Internet channel in the mar...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2015