Title
Secure Cyber Deception Architecture and Decoy Injection to Mitigate the Insider Threat.
Abstract
We propose a novel dynamic host mutation (DHM) architecture based on moving target defense (MTD) that can actively cope with cyberattacks. The goal of the DHM is to break the cyber kill chain, expand the attack surface to increase the attacker's target analysis cost, and disrupt the attacker's fingerprinting to disable the server trace. We define the participating entities that share the MTD policy within the enterprise network or the critical infrastructure, and define functional modules of each entity for DHM enforcement. The threat model of this study is an insider threat of a type not considered in previous studies. We define an attack model considering an insider threat and propose a decoy injection mechanism to confuse the attacker. In addition, we analyze the security of the proposed structure and mechanism based on the security requirements and propose a trade-off considering security and availability.
Year
DOI
Venue
2018
10.3390/sym10010014
SYMMETRY-BASEL
Keywords
Field
DocType
moving target defense,network security,proactive security,decoy injection
Attack model,Combinatorics,Attack surface,Kill chain,Threat model,Computer security,Network security,Critical infrastructure,Insider threat,Enterprise private network,Mathematics
Journal
Volume
Issue
ISSN
10
1
2073-8994
Citations 
PageRank 
References 
0
0.34
16
Authors
4
Name
Order
Citations
PageRank
Kyung Min Park142.20
Samuel Woo2272.50
Daesung Moon3102.57
Hoon Choi422523.95