A Receding-Horizon MDP Approach for Performance Evaluation of Moving Target Defense in Networks

02/07/2020
by   Zhentian Qian, et al.
0

In this paper, we study the problem of assessing the effectiveness of a proactive defense-by-detection policy with a network-based moving target defense. We model the network system using a probabilistic attack graph–a graphical security model. Given a network system with a proactive defense strategy, an intelligent attacker needs to repeatedly perform reconnaissance to learn about the locations of intrusion detection systems and re-plan optimally to reach the target while avoiding detection. To compute the attacker's strategy for security evaluation, we develop a receding-horizon planning algorithm in a risk-sensitive Markov decision process with a time-varying reward function. Finally, we implement both defense and attack strategies in a synthetic network and analyze how the frequency of network randomization and the number of detection systems can influence the success rate of the attacker. This study provides insights for designing proactive defense strategies against online and multi-stage attacks carried out by a resourceful attacker.

READ FULL TEXT
research
06/28/2022

Reasoning about Moving Target Defense in Attack Modeling Formalisms

Since 2009, Moving Target Defense (MTD) has become a new paradigm of def...
research
10/13/2022

Synthesis of Proactive Sensor Placement In Probabilistic Attack Graphs

This paper studies the deployment of joint moving target defense (MTD) a...
research
05/22/2019

Markov Decision Process to Enforce Moving Target Defence Policies

Moving Target Defense (MTD) is an emerging game-changing defense strateg...
research
03/25/2019

A cost-effective shuffling method against DDoS attacks using Moving Target Defense

Moving Target Defense(MTD) has emerged as a good solution to alter the a...
research
03/13/2023

Advancing Network Securing Strategies with Network Algorithms for Integrated Air Defense System (IADS) Missile Batteries

Recently, the Integrated Air Defense System (IADS) has become vital for ...
research
11/01/2018

Adaptive MTD Security using Markov Game Modeling

Large scale cloud networks consist of distributed networking and computi...
research
03/01/2023

Planning for Attacker Entrapment in Adversarial Settings

In this paper, we propose a planning framework to generate a defense str...

Please sign up or login with your details

Forgot password? Click here to reset