CHAOS: An SDN-Based Moving Target Defense System

المؤلفون المشاركون

Zhao, Bo
Hu, Hongxin
Shi, Yuan
Zhang, Huanguo
Wang, Juan
Xiao, Feng
Huang, Jianwei
Zha, Daochen
Yan, Fei

المصدر

Security and Communication Networks

العدد

المجلد 2017، العدد 2017 (31 ديسمبر/كانون الأول 2017)، ص ص. 1-11، 11ص.

الناشر

Hindawi Publishing Corporation

تاريخ النشر

2017-10-16

دولة النشر

مصر

عدد الصفحات

11

التخصصات الرئيسية

تكنولوجيا المعلومات وعلم الحاسوب

الملخص EN

Moving target defense (MTD) has provided a dynamic and proactive network defense to reduce or move the attack surface that is available for exploitation.

However, traditional network is difficult to realize dynamic and active security defense effectively and comprehensively.

Software-defined networking (SDN) points out a brand-new path for building dynamic and proactive defense system.

In this paper, we propose CHAOS, an SDN-based MTD system.

Utilizing the programmability and flexibility of SDN, CHAOS obfuscates the attack surface including host mutation obfuscation, ports obfuscation, and obfuscation based on decoy servers, thereby enhancing the unpredictability of the networking environment.

We propose the Chaos Tower Obfuscation (CTO) method, which uses the Chaos Tower Structure (CTS) to depict the hierarchy of all the hosts in an intranet and define expected connection and unexpected connection.

Moreover, we develop fast CTO algorithms to achieve a different degree of obfuscation for the hosts in each layer.

We design and implement CHAOS as an application of SDN controller.

Our approach makes it very easy to realize moving target defense in networks.

Our experimental results show that a network protected by CHAOS is capable of decreasing the percentage of information disclosure effectively to guarantee the normal flow of traffic.

نمط استشهاد جمعية علماء النفس الأمريكية (APA)

Shi, Yuan& Zhang, Huanguo& Wang, Juan& Xiao, Feng& Huang, Jianwei& Zha, Daochen…[et al.]. 2017. CHAOS: An SDN-Based Moving Target Defense System. Security and Communication Networks،Vol. 2017, no. 2017, pp.1-11.
https://search.emarefa.net/detail/BIM-1202879

نمط استشهاد الجمعية الأمريكية للغات الحديثة (MLA)

Shi, Yuan…[et al.]. CHAOS: An SDN-Based Moving Target Defense System. Security and Communication Networks No. 2017 (2017), pp.1-11.
https://search.emarefa.net/detail/BIM-1202879

نمط استشهاد الجمعية الطبية الأمريكية (AMA)

Shi, Yuan& Zhang, Huanguo& Wang, Juan& Xiao, Feng& Huang, Jianwei& Zha, Daochen…[et al.]. CHAOS: An SDN-Based Moving Target Defense System. Security and Communication Networks. 2017. Vol. 2017, no. 2017, pp.1-11.
https://search.emarefa.net/detail/BIM-1202879

نوع البيانات

مقالات

لغة النص

الإنجليزية

الملاحظات

Includes bibliographical references

رقم السجل

BIM-1202879