Spatio-temporal address mutation for proactive cyber agility against sophisticated attackers

  • Jafar Haadi Jafarian
  • , Ehab Al-Shaer
  • , Qi Duan

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

88 Scopus citations

Abstract

The static one-to-one binding of hosts to IP addresses allows adversaries to conduct thorough reconnaissance in order to discover and enumerate network assets. Specifically, this fixed address mapping allows distributed network scanners to aggregate information gathered at multiple locations over different times in order to construct an accurate and persistent view of the network. The unvarying nature of this view enables adversaries to collaboratively share and reuse their collected reconnaissance information in various stages of attack planning and execution. This paper presents a novel moving target defense (MTD) technique which enables host-to-IP binding of each destination host to vary randomly across the network based on the source identity (spatial randomization) as well as time (temporal randomization). This spatio-temporal randomization will distort attackers' view of the network by causing the collected reconnaissance information to expire as adversaries transition from one host to another or if they stay long enough in one location. Consequently, adversaries are forced to re-scan the network frequently at each location or over different time intervals. These recurring probings significantly raises the bar for the adversaries by slowing down the attack progress, while improving its detectability. We introduce three novel metrics for quantifying the effectiveness of MTD defense techniques: deterrence, deception, and detectability. Using these metrics, we perform rigorous theoretical and experimental analysis to evaluate the efficacy of this approach. These analyses show that our approach is effective in countering a significant number of sophisticated threat models including collaborative reconnaissance, worm propagation, and advanced persistent threat (APT), in an evasion-free manner.

Original languageEnglish
Title of host publicationMTD 2014 - Proceedings of the 2014 ACM Workshop on Moving Target Defense, Co-located with CCS 2014
PublisherAssociation for Computing Machinery
Pages69-78
Number of pages10
EditionNovember
ISBN (Print)9781450331500
DOIs
StatePublished - 7 Nov 2014
Externally publishedYes
Event1st ACM Workshop on Moving Target Defense, MTD 2014 - Co-located with 21st ACM Conference on Computer and Communications Security, CCS 2014 - Scottsdale, United States
Duration: 3 Nov 2014 → …

Publication series

NameProceedings of the ACM Conference on Computer and Communications Security
NumberNovember
Volume2014-November
ISSN (Print)1543-7221

Conference

Conference1st ACM Workshop on Moving Target Defense, MTD 2014 - Co-located with 21st ACM Conference on Computer and Communications Security, CCS 2014
Country/TerritoryUnited States
CityScottsdale
Period3/11/14 → …

Bibliographical note

Publisher Copyright:
Copyright © 2014 by the Association for Computing Machinery, Inc. (ACM).

Keywords

  • Adversary-awareness
  • IP address randomization
  • Moving target defense (MTD)
  • Reconnaissance

ASJC Scopus subject areas

  • Software
  • Computer Networks and Communications

Fingerprint

Dive into the research topics of 'Spatio-temporal address mutation for proactive cyber agility against sophisticated attackers'. Together they form a unique fingerprint.

Cite this