Computer networks may never float like a butterfly, but Penn State information scientists suggest that creating nimble networks that can sense jabs from hackers could help deflect the stinging blows of those attacks.
“Because of the static nature of a computer network, the attacker has a time advantage,” said Dinghao Wu, assistant professor of information sciences and technology. “Hackers can spend a month, two months, six months or more just studying the network and finding vulnerabilities. When they return to use that information to attack, the network typically has not changed and those vulnerabilities are still there, too.”
The researchers, who release their findings at the Information Security Conference held in Honolulu today (Sept. 8), created a computer defense system that senses possible malicious probes of the network and then redirects that attack to a virtual network that offers little information about the real network.
Typically, the first step a hacker takes when attacking a network is a probe to gain information about the system — for example, what software types and versions, operating systems and hardware the network is running. Instead of trying to stop these hackers’ scans, researchers set up a detector to monitor incoming web traffic to determine when hackers are scanning the network.
“We can’t realistically stop all scanning activities, but we can usually tell when a malicious scan is happening,” said Wu. “If it’s a large-scale scan, it is usually malicious.”
Once a malicious scan is detected, the researchers use a network device — called a reflector — to redirect that traffic to a decoy, or shadow network, according to Li Wang, a doctoral candidate in information sciences and technology, who worked with Wu. The shadow network is isolated and invisible from the real network, but can mimic the structure of a physical network to fool the hackers into believing they are receiving information about an actual network.
“A typical strategy would be to create a shadow network environment that has the same look as the protection domain,” said Wang. “It can have the same number of nodes, network topology and configurations to fool the hacker. These shadow networks can be created to simulate complex network structures.”
The system, which is a type of defense known in the computer industry as a moving target defense, also gives network administrators the option to more easily change parts of the shadow network’s virtual system, making it even more difficult for hackers to assess the success of their scans.
Because the reflector can act as a regular network device when no malicious attacks are present, there should be little effect on the real network’s performance and functionality, according to Wu.
The researchers created a prototype for the system and tested it on a simulated network that runs on a computer — a virtual local area network. This allowed them to simulate both the attack and defense without using an actual network. The prototype was able to sense the incoming scan and deflect it to a shadow network.
According to the researchers, the information that was gathered from the attack scan only produced information from the shadow network.
Wu said the next step is to deploy the system in an actual network.
The Latest on: Moving target defense
via Google News
The Latest on: Moving target defense
- Hapag-Lloyd Aktiengesellschaft (OTCMKTS:HPGLY) Price Target Raised to €330.00 at Morgan Stanleyon May 15, 2022 at 6:50 am
Hapag-Lloyd Aktiengesellschaft (OTCMKTS:HPGLY – Get Rating) had its price objective increased by research analysts at Morgan Stanley from €305.00 ($321.05) to €330.00 ($347.37) in a note issued to ...
- Canaccord Genuity Group Trims Greenlane Renewables (OTCMKTS:GRNWF) Target Price to C$1.90on May 15, 2022 at 6:50 am
Greenlane Renewables (OTCMKTS:GRNWF – Get Rating) had its price target cut by Canaccord Genuity Group from C$2.25 to C$1.90 in a research report issued to clients and investors on Sunday, The Fly ...
- Kratos Defense & Security Solutions, Inc. (NASDAQ:KTOS) Given Consensus Rating of “Buy” by Brokerageson May 14, 2022 at 3:47 am
The average 12 month target price among brokerages that have updated ... The company’s 50 day moving average price is $18.16 and its 200-day moving average price is $18.78. Kratos Defense & Security ...
- USAF: Hypersonic Development Needs To Focus On Moving Targetson May 13, 2022 at 11:23 am
USAF: Hypersonic Development Needs To Focus On Moving Targets is published in Aerospace Daily & Defense Report, an Aviation Week Intelligence Network (AWIN) Market Briefing and is included with ...
- This is the $13 billion US Navy aircraft carrier Trump constantly complained looked 'really bad,' according to his former defense chiefon May 11, 2022 at 2:26 pm
Trump's former defense secretary said that he had tried to address Trump's complaints about the ship many times but eventually just gave up.
- Teledyne FLIR Defense Introduces New Laser Target Designator Payload for Small (Group 1) Unmanned Aerial Systemson May 10, 2022 at 4:00 am
Groundbreaking StormCaster-DX payload offers capability previously available only on Group 4 drones or ground-based systems; A powerful new ‘force multiplier’ for small units who can now designate ...
- Japan’s push to double defense spending ties directly back to Ukraineon May 9, 2022 at 4:25 pm
"What this document says is, we have to anticipate this (Ukraine) emergency. Don't wait till it's upon us," said Rikki Kersten, honorary professor at the Australian National University.
- Melrose Industries (OTCMKTS:MLSPF) Price Target Cut to GBX 215 by Analysts at JPMorgan Chase & Co.on May 5, 2022 at 8:48 am
Melrose Industries (OTCMKTS:MLSPF – Get Rating) had its price target lowered by JPMorgan Chase & Co. from GBX 240 ($3.00) to GBX 215 ($2.69) in a report published on Wednesday, The Fly reports.
- Defense & National Security — More Ukrainians trained on US weaponson May 4, 2022 at 5:01 pm
The U.S. military is ramping up its weapons training for Ukrainian forces, with hundreds now being trained on artillery systems, drones and radars. We’ll detail where they are being ...
via Bing News