Investigating the Application of Moving Target Defenses to Network Security
Abstract:
This paper presents a preliminary design for a moving-target defense 201MTD202 for computer networks to combat an attackers asymmetric advantage. The MTD system reasons over a set of abstract models that capture the networks configuration and its operational and security goals to select adaptations that maintain the operational integrity of the network. The paper examines both a simple 201purely random202 MTD system as well as an intelligent MTD system that uses attack indicators to augment adaptation selection. A set of simulation-based experiments show that such an MTD system may in fact be able to reduce an attackers success likelihood. These results are a preliminary step towards understanding and quantifying the impact of MTDs on computer networks.