Chhoyhopper: A Moving Target Defense with IPv6

05/28/2021
by   ASM Rizvi, et al.
0

Services on the public Internet are frequently scanned, then subject to brute-force and denial-of-service attacks. We would like to run such services stealthily, available to friends but hidden from adversaries. In this work, we propose a moving target defense named "Chhoyhopper" that utilizes the vast IPv6 address space to conceal publicly available services. The client and server to hop to different IPv6 addresses in a pattern based on a shared, pre-distributed secret and the time-of-day. By hopping over a /64 prefix, services cannot be found by active scanners, and passively observed information is useless after two minutes. We demonstrate our system with SSH, and show that it can be extended to other applications.

READ FULL TEXT

page 1

page 2

page 3

research
12/04/2017

Changing proxy-server identities as a proactive moving-target defense against reconnaissance for DDoS attacks

We consider a cloud based multiserver system consisting of a set of repl...
research
01/11/2019

Don't Wait to be Breached! Creating Asymmetric Uncertainty of Cloud Applications via Moving Target Defenses

Cloud applications expose - besides service endpoints - also potential o...
research
10/07/2021

MPD: Moving Target Defense through Communication Protocol Dialects

Communication protocol security is among the most significant challenges...
research
03/17/2023

Moving Target Defense for Service-oriented Mission-critical Networks

Modern mission-critical systems (MCS) are increasingly softwarized and i...
research
09/15/2022

Defending Root DNS Servers Against DDoS Using Layered Defenses

Distributed Denial-of-Service (DDoS) attacks exhaust resources, leaving ...
research
01/03/2018

ARTEMIS: Neutralizing BGP Hijacking within a Minute

BGP prefix hijacking is a critical threat to Internet organizations and ...
research
03/02/2023

Predicting IPv4 Services Across All Ports

Internet-wide scanning is commonly used to understand the topology and s...

Please sign up or login with your details

Forgot password? Click here to reset