Title
Attack Surface Expansion Using Decoys to Protect Virtualized Infrastructure
Abstract
As cloud services using the virtualized technique are emerging and developing rapidly, protection of cloud services is a key issue. Most research efforts focus on reducing the attack surface observed by the external attackers, which is an impractical solution for a complex system like virtualized infrastructure. In order to deceive the attackers and waste their time and efforts, three attack surface expansion approaches for moving target defense are proposed in this paper. These three approaches provide different protection capability with different system complexity by using decoy virtual machines that co-exist with the real virtual machines in the same physical host. The probability that the external attacker successfully exploits the valid assets is theoretically analyzed. Simulation results show the attackers' success rate can be significantly reduced by adding decoy virtual machines. Simulation results also show that the greater the knowledge about the attackers' capability, the better protection the proposed approaches can provide.
Year
DOI
Venue
2017
10.1109/IEEE.EDGE.2017.38
2017 IEEE International Conference on Edge Computing (EDGE)
Keywords
DocType
ISBN
Virtualized Infrastructure,Moving Target Defense,Decoy Virtual Machine,Attack Surface Expansion
Conference
978-1-5386-2018-2
Citations 
PageRank 
References 
1
0.36
0
Authors
3
Name
Order
Citations
PageRank
Tulha Al-Salah110.36
Liang Hong219333.79
Sachin Shetty332355.94