论文标题

评估行动目标防御技术对云的安全和经济影响

Evaluating the Security and Economic Effects of Moving Target Defense Techniques on the Cloud

论文作者

Alavizadeh, Hooman, Aref, Samin, Kim, Dong Seong, Jang-Jaccard, Julian

论文摘要

移动目标防御(MTD)是一种主动的安全机制,它改变了旨在混淆攻击者的攻击表面。云计算利用MTD技术来增强针对网络威胁的云安全姿势。尽管许多MTD技术已应用于云计算,但尚未对MTD技术在安全和经济指标上的有效性进行联合评估。在本文中,我们首先介绍了三种MTD技术组合的数学定义:\ emph {shuffle},\ emph {多样性}和\ emph {redundancy}。然后,我们利用四个安全指标,包括系统风险,攻击成本,攻击回报和可靠性来评估应用于大规模云模型的合并MTD技术的有效性。其次,我们专注于基于电子健康应用程序的云模型的特定环境,以使用安全和经济指标评估MTD技术的有效性。我们介绍了(1)一种使用虚拟机放置技术有效地部署洗牌MTD技术的策略,以及(2)两种通过操作系统多元化部署多样性MTD技术的策略。随着部署多样性的成本,我们制定了\ emph {最佳多样性分配问题(O-DAP)},并将其作为二进制线性编程模型解决,以获得最大化预期净福利的分配。

Moving Target Defense (MTD) is a proactive security mechanism which changes the attack surface aiming to confuse attackers. Cloud computing leverages MTD techniques to enhance cloud security posture against cyber threats. While many MTD techniques have been applied to cloud computing, there has not been a joint evaluation of the effectiveness of MTD techniques with respect to security and economic metrics. In this paper, we first introduce mathematical definitions for the combination of three MTD techniques: \emph{Shuffle}, \emph{Diversity}, and \emph{Redundancy}. Then, we utilize four security metrics including system risk, attack cost, return on attack, and reliability to assess the effectiveness of the combined MTD techniques applied to large-scale cloud models. Secondly, we focus on a specific context based on a cloud model for E-health applications to evaluate the effectiveness of the MTD techniques using security and economic metrics. We introduce (1) a strategy to effectively deploy Shuffle MTD technique using a virtual machine placement technique and (2) two strategies to deploy Diversity MTD technique through operating system diversification. As deploying Diversity incurs cost, we formulate the \emph{Optimal Diversity Assignment Problem (O-DAP)} and solve it as a binary linear programming model to obtain the assignment which maximizes the expected net benefit.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源