Skip to main navigation Skip to search Skip to main content

Reasoning about Moving Target Defense in Attack Modeling Formalisms

  • Institut Polytechnique de Paris

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Since 2009, Moving Target Defense (MTD) has become a new paradigm of defensive mechanism that frequently changes the state of the target system to confuse the attacker. This frequent change is costly and leads to a trade-off between misleading the attacker and disrupting the quality of service. Optimizing the MTD activation frequency is necessary to develop this defense mechanism when facing realistic, multi-step attack scenarios. Attack modeling formalisms based on DAG are prominently used to specify these scenarios. Our contribution is a new DAG-based formalism for MTDs and its translation into a Price Timed Markov Decision Process to find the best activation frequencies against the attacker's time/cost optimal strategies. For the first time, MTD activation frequencies are analyzed in a state-of-the-art DAG-based representation. Moreover, this is the first paper that considers the specificity of MTDs in the automatic analysis of attack modeling formalisms. Finally, we present some experimental results using Uppaal Stratego to demonstrate its applicability and relevance.

Original languageEnglish
Title of host publicationMTD 2022 - Proceedings of the 9th ACM Workshop on Moving Target Defense, co-located with CCS 2022
PublisherAssociation for Computing Machinery, Inc
Pages55-65
Number of pages11
ISBN (Electronic)9781450398787
DOIs
Publication statusPublished - 11 Nov 2022
Event9th ACM Workshop on Moving Target Defense, MTD 2022 - Co-located with CCS 2022 - Los Angeles, United States
Duration: 7 Nov 2022 → …

Publication series

NameMTD 2022 - Proceedings of the 9th ACM Workshop on Moving Target Defense, co-located with CCS 2022

Conference

Conference9th ACM Workshop on Moving Target Defense, MTD 2022 - Co-located with CCS 2022
Country/TerritoryUnited States
CityLos Angeles
Period7/11/22 → …

Keywords

  • cyber security
  • moving target defense
  • threat modeling
  • timed model checking

Fingerprint

Dive into the research topics of 'Reasoning about Moving Target Defense in Attack Modeling Formalisms'. Together they form a unique fingerprint.

Cite this