Michael Thompson, Nathaniel Evans, Victoria Kisekka
{"title":"Multiple OS rotational environment an implemented Moving Target Defense","authors":"Michael Thompson, Nathaniel Evans, Victoria Kisekka","doi":"10.1109/ISRCS.2014.6900086","DOIUrl":null,"url":null,"abstract":"Cyber-attacks continue to pose a major threat to existing critical infrastructure. Although suggestions for defensive strategies abound, Moving Target Defense (MTD) has only recently gained attention as a possible solution for mitigating cyber-attacks. The current work proposes a MTD technique that provides enhanced security through a rotation of multiple operating systems. The MTD solution developed in this research utilizes existing technology to provide a feasible dynamic defense solution that can be deployed easily in a real networking environment. In addition, the system we developed was tested extensively for effectiveness using CORE Impact Pro (CORE), Nmap, and manual penetration tests. The test results showed that platform diversity and rotation offer improved security. In addition, the likelihood of a successful attack decreased proportionally with time between rotations.","PeriodicalId":205922,"journal":{"name":"2014 7th International Symposium on Resilient Control Systems (ISRCS)","volume":"33 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2014-09-18","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"39","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2014 7th International Symposium on Resilient Control Systems (ISRCS)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ISRCS.2014.6900086","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 39
Abstract
Cyber-attacks continue to pose a major threat to existing critical infrastructure. Although suggestions for defensive strategies abound, Moving Target Defense (MTD) has only recently gained attention as a possible solution for mitigating cyber-attacks. The current work proposes a MTD technique that provides enhanced security through a rotation of multiple operating systems. The MTD solution developed in this research utilizes existing technology to provide a feasible dynamic defense solution that can be deployed easily in a real networking environment. In addition, the system we developed was tested extensively for effectiveness using CORE Impact Pro (CORE), Nmap, and manual penetration tests. The test results showed that platform diversity and rotation offer improved security. In addition, the likelihood of a successful attack decreased proportionally with time between rotations.
网络攻击继续对现有的关键基础设施构成重大威胁。尽管关于防御策略的建议很多,但移动目标防御(MTD)作为缓解网络攻击的可能解决方案直到最近才引起人们的注意。目前的工作提出了一种MTD技术,该技术通过多个操作系统的轮换提供增强的安全性。本研究开发的MTD解决方案利用现有技术提供了一种可行的动态防御解决方案,可以在真实的网络环境中轻松部署。此外,我们开发的系统使用CORE Impact Pro (CORE)、Nmap和手动渗透测试进行了广泛的有效性测试。测试结果表明,平台的多样性和轮换提高了安全性。此外,攻击成功的可能性随着轮换之间的时间而成比例地降低。