Proactive Defense for Internet-of-Things: Integrating Moving Target Defense with Cyberdeception

05/08/2020
by   Mengmeng Ge, et al.
0

Resource constrained Internet-of-Things (IoT) devices are highly likely to be compromised by attackers because strong security protections may not be suitable to be deployed. This requires an alternative approach to protect vulnerable components in IoT networks. In this paper, we propose an integrated defense technique to achieve intrusion prevention by leveraging cyberdeception (i.e., a decoy system) and moving target defense (i.e., network topology shuffling). We verify the effectiveness and efficiency of our proposed technique analytically based on a graphical security model in a software defined networking (SDN)-based IoT network. We develop four strategies (i.e., fixed/random and adaptive/hybrid) to address "when" to perform network topology shuffling and three strategies (i.e., genetic algorithm/decoy attack path-based optimization/random) to address "how" to perform network topology shuffling on a decoy-populated IoT network, and analyze which strategy can best achieve a system goal such as prolonging the system lifetime, maximizing deception effectiveness, maximizing service availability, or minimizing defense cost. Our results demonstrate that a software defined IoT network running our intrusion prevention technique at the optimal parameter setting prolongs system lifetime, increases attack complexity of compromising critical nodes, and maintains superior service availability compared with a counterpart IoT network without running our intrusion prevention technique. Further, when given a single goal or a multi-objective goal (e.g., maximizing the system lifetime and service availability while minimizing the defense cost) as input, the best combination of "how" and "how" strategies is identified for executing our proposed technique under which the specified goal can be best achieved.

READ FULL TEXT

page 12

page 17

research
08/01/2019

Modeling and Analysis of Integrated Proactive Defense Mechanisms for Internet-of-Things

As a solution to protect and defend a system against inside attacks, man...
research
08/01/2019

Optimal Deployments of Defense Mechanisms for the Internet of Things

Internet of Things (IoT) devices can be exploited by the attackers as en...
research
03/15/2020

SOM-based DDoS Defense Mechanism using SDN for the Internet of Things

To effectively tackle the security threats towards the Internet of thing...
research
04/01/2021

Too Expensive to Attack: A Joint Defense Framework to Mitigate Distributed Attacks for the Internet of Things Grid

The distributed denial of service (DDoS) attack is detrimental to busine...
research
06/05/2018

Enabling Cooperative IoT Security via Software Defined Networks (SDN)

Internet of Things (IoT) is becoming an increasingly attractive target f...
research
10/07/2021

MPD: Moving Target Defense through Communication Protocol Dialects

Communication protocol security is among the most significant challenges...
research
11/16/2018

Protecting Voice Controlled Systems Using Sound Source Identification Based on Acoustic Cues

Over the last few years, a rapidly increasing number of Internet-of-Thin...

Please sign up or login with your details

Forgot password? Click here to reset