{"title":"改进敏捷和移动目标防御的静态分析机会","authors":"T. Jaeger","doi":"10.1145/3411496.3421230","DOIUrl":null,"url":null,"abstract":"Agile defenses have been proposed to enable systems to change their defensive posture dynamically to thwart attacks. Researchers have suggested a variety of agile defenses that leverage renaming (e.g., for network services), migration (e.g., for cloud instances), variation (e.g., for application configurations), and patching (e.g., for programs), among others. These agile defenses demonstrate promise for achieving a key goal: increasing the cost of launching a successful attack. However, agile defenses also incur non-trivial costs in overhead and/or complexity to defenders as well, leaving defenders hesitant to employ such defenses without further justification for their necessity. A question we examine in this keynote is how to develop techniques that may aid defenders in choosing when to employ agile defenses and which agile defenses to employ.","PeriodicalId":288218,"journal":{"name":"Proceedings of the 7th ACM Workshop on Moving Target Defense","volume":"450 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2020-11-09","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Static Analysis Opportunities for Improving Agile and Moving Target Defenses\",\"authors\":\"T. Jaeger\",\"doi\":\"10.1145/3411496.3421230\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Agile defenses have been proposed to enable systems to change their defensive posture dynamically to thwart attacks. Researchers have suggested a variety of agile defenses that leverage renaming (e.g., for network services), migration (e.g., for cloud instances), variation (e.g., for application configurations), and patching (e.g., for programs), among others. These agile defenses demonstrate promise for achieving a key goal: increasing the cost of launching a successful attack. However, agile defenses also incur non-trivial costs in overhead and/or complexity to defenders as well, leaving defenders hesitant to employ such defenses without further justification for their necessity. A question we examine in this keynote is how to develop techniques that may aid defenders in choosing when to employ agile defenses and which agile defenses to employ.\",\"PeriodicalId\":288218,\"journal\":{\"name\":\"Proceedings of the 7th ACM Workshop on Moving Target Defense\",\"volume\":\"450 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2020-11-09\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Proceedings of the 7th ACM Workshop on Moving Target Defense\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1145/3411496.3421230\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of the 7th ACM Workshop on Moving Target Defense","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/3411496.3421230","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
Static Analysis Opportunities for Improving Agile and Moving Target Defenses
Agile defenses have been proposed to enable systems to change their defensive posture dynamically to thwart attacks. Researchers have suggested a variety of agile defenses that leverage renaming (e.g., for network services), migration (e.g., for cloud instances), variation (e.g., for application configurations), and patching (e.g., for programs), among others. These agile defenses demonstrate promise for achieving a key goal: increasing the cost of launching a successful attack. However, agile defenses also incur non-trivial costs in overhead and/or complexity to defenders as well, leaving defenders hesitant to employ such defenses without further justification for their necessity. A question we examine in this keynote is how to develop techniques that may aid defenders in choosing when to employ agile defenses and which agile defenses to employ.