@article{ART002385932},
author={Tae-Keun Park and Kyungmin Park and Daesung Moon},
title={Design of a Protected Server Network with Decoys for Network-based Moving Target Defense},
journal={Journal of The Korea Society of Computer and Information},
issn={1598-849X},
year={2018},
volume={23},
number={9},
pages={57-64},
doi={10.9708/jksci.2018.23.09.057}
TY - JOUR
AU - Tae-Keun Park
AU - Kyungmin Park
AU - Daesung Moon
TI - Design of a Protected Server Network with Decoys for Network-based Moving Target Defense
JO - Journal of The Korea Society of Computer and Information
PY - 2018
VL - 23
IS - 9
PB - The Korean Society Of Computer And Information
SP - 57
EP - 64
SN - 1598-849X
AB - In recent years, a new approach to cyber security, called the moving target defense, has emerged as a potential solution to the challenge of static systems. In this paper, we design a protected server network with a large number of decoys to anonymize the protected servers that dynamically mutate their IP address and port numbers according to Hidden Tunnel Networking, which is a network-based moving target defense scheme. In the network, a protected server is one-to-one mapped to a decoy-bed that generates a number of decoys, and the decoys share the same IP address pool with the protected server. First, the protected server network supports mutating the IP address and port numbers of the protected server very frequently regardless of the number of decoys. Second, it provides independence of the decoy-bed configuration. Third, it allows the protected servers to freely change their IP address pool. Lastly, it can reduce the possibility that an attacker will reuse the discovered attributes of a protected server in previous scanning. We believe that applying Hidden Tunnel Networking to protected servers in the proposed network can significantly reduce the probability of the protected servers being identified and compromised by attackers through deploying a large number of decoys.
KW - Network-based moving target defense;mutation;cyber security;protected server;decoy
DO - 10.9708/jksci.2018.23.09.057
ER -
Tae-Keun Park, Kyungmin Park and Daesung Moon. (2018). Design of a Protected Server Network with Decoys for Network-based Moving Target Defense. Journal of The Korea Society of Computer and Information, 23(9), 57-64.
Tae-Keun Park, Kyungmin Park and Daesung Moon. 2018, "Design of a Protected Server Network with Decoys for Network-based Moving Target Defense", Journal of The Korea Society of Computer and Information, vol.23, no.9 pp.57-64. Available from: doi:10.9708/jksci.2018.23.09.057
Tae-Keun Park, Kyungmin Park, Daesung Moon "Design of a Protected Server Network with Decoys for Network-based Moving Target Defense" Journal of The Korea Society of Computer and Information 23.9 pp.57-64 (2018) : 57.
Tae-Keun Park, Kyungmin Park, Daesung Moon. Design of a Protected Server Network with Decoys for Network-based Moving Target Defense. 2018; 23(9), 57-64. Available from: doi:10.9708/jksci.2018.23.09.057
Tae-Keun Park, Kyungmin Park and Daesung Moon. "Design of a Protected Server Network with Decoys for Network-based Moving Target Defense" Journal of The Korea Society of Computer and Information 23, no.9 (2018) : 57-64.doi: 10.9708/jksci.2018.23.09.057
Tae-Keun Park; Kyungmin Park; Daesung Moon. Design of a Protected Server Network with Decoys for Network-based Moving Target Defense. Journal of The Korea Society of Computer and Information, 23(9), 57-64. doi: 10.9708/jksci.2018.23.09.057
Tae-Keun Park; Kyungmin Park; Daesung Moon. Design of a Protected Server Network with Decoys for Network-based Moving Target Defense. Journal of The Korea Society of Computer and Information. 2018; 23(9) 57-64. doi: 10.9708/jksci.2018.23.09.057
Tae-Keun Park, Kyungmin Park, Daesung Moon. Design of a Protected Server Network with Decoys for Network-based Moving Target Defense. 2018; 23(9), 57-64. Available from: doi:10.9708/jksci.2018.23.09.057
Tae-Keun Park, Kyungmin Park and Daesung Moon. "Design of a Protected Server Network with Decoys for Network-based Moving Target Defense" Journal of The Korea Society of Computer and Information 23, no.9 (2018) : 57-64.doi: 10.9708/jksci.2018.23.09.057