A theory for understanding and quantifying moving target defense

dc.contributor.authorZhuang, Rui
dc.date.accessioned2015-11-18T19:03:27Z
dc.date.available2015-11-18T19:03:27Z
dc.date.graduationmonthDecemberen_US
dc.date.issued2015-12-01en_US
dc.date.published2015en_US
dc.description.abstractThe static nature of cyber systems gives attackers a valuable and asymmetric advantage - time. To eliminate this asymmetric advantage, a new approach, called Moving Target Defense (MTD) has emerged as a potential solution. MTD system seeks to proactively change system configurations to invalidate the knowledge learned by the attacker and force them to spend more effort locating and re-locating vulnerabilities. While it sounds promising, the approach is so new that there is no standard definition of what an MTD is, what is meant by diversification and randomization, or what metrics to define the effectiveness of such systems. Moreover, the changing nature of MTD violates two basic assumptions about the conventional attack surface notion. One is that the attack surface remains unchanged during an attack and the second is that it is always reachable. Therefore, a new attack surface definition is needed. To address these issues, I propose that a theoretical framework for MTD be defined. The framework should clarify the most basic questions such as what an MTD system is and its properties such as adaptation, diversification and randomization. The framework should reveal what is meant by gaining and losing knowledge, and what are different attack types. To reason over the interactions between attacker and MTD system, the framework should define key concepts such as attack surface, adaptation surface and engagement surface. Based on that, this framework should allow MTD system designers to decide how to use existing configuration choices and functionality diversification to increase security. It should allow them to analyze the effectiveness of adapting various combinations of different configuration aspects to thwart different types of attacks. To support analysis, the frame- work should include an analytical model that can be used by designers to determine how different parameter settings will impact system security.en_US
dc.description.advisorScott A. DeLoachen_US
dc.description.degreeDoctor of Philosophyen_US
dc.description.departmentComputing and Information Sciencesen_US
dc.description.levelDoctoralen_US
dc.description.sponsorshipU.S. Air Force Office of Scientific Research, U.S. National Science Foundationen_US
dc.identifier.urihttp://hdl.handle.net/2097/20525
dc.language.isoenen_US
dc.publisherKansas State Universityen
dc.subjectMoving Target Defenseen_US
dc.subjectNetwork Securityen_US
dc.subjectComputer Securityen_US
dc.subjectScience of Securityen_US
dc.subjectCloud Securityen_US
dc.subject.umiComputer Science (0984)en_US
dc.titleA theory for understanding and quantifying moving target defenseen_US
dc.typeDissertationen_US

Files

Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
RuiZhuang2015.pdf
Size:
2.96 MB
Format:
Adobe Portable Document Format
Description:
Dissertation
License bundle
Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
1.62 KB
Format:
Item-specific license agreed upon to submission
Description: