본문 바로가기
  • Home

Attack Surface Expansion through Decoy Trap for Protected Servers in Moving Target Defense

  • Journal of The Korea Society of Computer and Information
  • Abbr : JKSCI
  • 2019, 24(10), pp.25-32
  • DOI : 10.9708/jksci.2019.24.10.025
  • Publisher : The Korean Society Of Computer And Information
  • Research Area : Engineering > Computer Science
  • Received : September 18, 2019
  • Accepted : October 7, 2019
  • Published : October 31, 2019

Tae-Keun Park 1 Kyungmin Park 2 Daesung Moon 2

1단국대학교
2한국전자통신연구원

Accredited

ABSTRACT

In this paper, we propose a method to apply the attack surface expansion through decoy traps to a protected server network. The network consists of a large number of decoys and protected servers. In the network, each protected server dynamically mutates its IP address and port numbers based on Hidden Tunnel Networking that is a network-based moving target defense scheme. The moving target defense is a new approach to cyber security and continuously changes system’s attack surface to prevent attacks. And, the attack surface expansion is an approach that uses decoys and decoy groups to protect attacks. The proposed method modifies the NAT table of the protected server with a custom chain and a RETURN target in order to make attackers waste all their time and effort in the decoy traps. We theoretically analyze the attacker success rate for the protected server network before and after applying the proposed method. The proposed method is expected to significantly reduce the probability that a protected server will be identified and compromised by attackers.

Citation status

* References for papers published after 2023 are currently being built.