Visible to the public A System Attack Surface Based MTD Effectiveness and Cost Quantification Framework

TitleA System Attack Surface Based MTD Effectiveness and Cost Quantification Framework
Publication TypeConference Paper
Year of Publication2018
AuthorsXiong, Xinli, Zhao, Guangsheng, Wang, Xian
Conference NameProceedings of the 2Nd International Conference on Cryptography, Security and Privacy
PublisherACM
Conference LocationNew York, NY, USA
ISBN Number978-1-4503-6361-7
Keywordsattack surface, Chained Attacks, Metrics, moving target defense, Predictive Metrics, pubcrawl, Quantification Framework, resilience, Resiliency, Scalability, System Attack Surface
Abstract

Moving Target Defense (MTD) is a game-changing method to thwart adversaries and reverses the imbalance situation in network countermeasures. Introducing Attack Surface (AS) into MTD security assessment brings productive concepts to qualitative and quantitative analysis. The quantification of MTD effectiveness and cost (E&C) has been under researched, using simulation models and emulation testbeds, to give accurate and reliable results for MTD technologies. However, the lack of system-view evaluation impedes MTD to move toward large-scale applications. In this paper, a System Attack Surface Based Quantification Framework (SASQF) is proposed to establish a system-view based framework for further research in Attack Surface and MTD E&C quantification. And a simulated model based on SASQF is developed to provide illustrations and software simulation methods. A typical C/S scenario and Cyber Kill Chain (CKC) attacks are presented in case study and several simulated results are given. From the simulated results, IP mutation frequency is the key to increase consumptions of adversaries, while the IP mutation pool is not the principal factor to thwart adversaries in reconnaissance and delivery of CKC steps. For system user operational cost, IP mutation frequency influence legitimate connections in relative values under ideal link state without delay, packet lose and jitter. The simulated model based on SASQF also provides a basic method to find the optimal IP mutation frequency through simulations.

URLhttps://dl.acm.org/citation.cfm?doid=3199478.3199487
DOI10.1145/3199478.3199487
Citation Keyxiong_system_2018