Deception in Network Defences Using Unpredictability
نویسندگان
چکیده
In this article, we propose a novel method that aims to improve upon existing moving-target defences by making them unpredictably reactive using probabilistic decision-making. We postulate unpredictability can network in two key capacities: (1) re-configuring the direct response detected threats, tailored current threat and security posture, (2) deceiving adversaries pseudo-random decision-making (selected from set of acceptable responses), potentially leading adversary delay failure. Decisions are performed automatically, based on reported events (e.g., Intrusion Detection System (IDS) alerts), mission processes, states assets. Using codified form situational awareness, our system respond differently threats each time attacker activity is observed, acting as barrier further activities. demonstrate feasibility with both anomaly- misuse-based detection alerts, for historical dataset (playback), real-time simulation where asset-to-mission mappings known. Our findings suggest yields promise new approach deception laboratory settings. Further research will be necessary explore production environments.
منابع مشابه
The Case for Unpredictability and Deception as OS Features
The conventional wisdom is that OS APIs should behave predictably, facilitating software development. From a system security perspective, this predictability creates a disproportionate advantage for attackers. Could making OSes behave unpredictably create a disproportionate advantage for system defenders—significantly increasing the effort to create malware and attacks without too much inconven...
متن کاملImplementing network defence using deception in a wireless honeypot
The advance of 802.11b wireless networking has been beset by inherent and in-built security problems. Network security tools that are freely available may intercept network transmissions readily and with stealth, making organisations highly vulnerable to attack. Deception is an essential element of effective security that has been used in networks to understand attack methods and intrusions. Th...
متن کاملUnpredictability of deception in compliance with physician-prescribed bronchodilator inhaler use in a clinical trial.
OBJECTIVE To identify subject characteristics that may be predictive of intentional dumping of metered-dose inhalers (MDIs) during a clinical trial. DESIGN Nebulizer Chronologs (NCs; Medtrac Technologies; Lakewood, CO), which record the date and time of each MDI actuation, were attached to the MDIs of participants who were given a prescribed medication schedule to follow in a clinical trial. ...
متن کاملassessment of the efficiency of s.p.g.c refineries using network dea
data envelopment analysis (dea) is a powerful tool for measuring relative efficiency of organizational units referred to as decision making units (dmus). in most cases dmus have network structures with internal linking activities. traditional dea models, however, consider dmus as black boxes with no regard to their linking activities and therefore do not provide decision makers with the reasons...
Condensed Unpredictability
We consider the task of deriving a key with high HILL entropy (i.e., being computationally indistinguishable from a key with high min-entropy) from an unpredictable source. Previous to this work, the only known way to transform unpredictability into a key that was indistinguishable from having min-entropy was via pseudorandomness, for example by Goldreich-Levin (GL) hardcore bits. This approach...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
ژورنال
عنوان ژورنال: Digital threats
سال: 2021
ISSN: ['2692-1626', '2576-5337']
DOI: https://doi.org/10.1145/3450973