Journal on Communications ›› 2017, Vol. 38 ›› Issue (3): 133-143.doi: 10.11959/j.issn.1000-436x.2017056

• Papers • Previous Articles     Next Articles

Network moving target defense technique based on optimal forwarding path migration

Cheng LEI1,2,3,Duo-he MA2(),Hong-qi ZHANG1,3,Qi HAN4,Ying-jie YANG1,3   

  1. 1 Cryptography Engineering Institute,PLA Information Engineering University,Zhengzhou 450001,China
    2 State Key Laboratory of Information Security,Institute of Information Engineering,CAS,Beijing 100093,China
    3 Henan Key Laboratory of Information Security,Zhengzhou 450001,China
    4 Institute of Information Countermeasure Techniques,Harbin Institute of Technology,Harbin 150001,China
  • Revised:2017-02-05 Online:2017-03-01 Published:2017-04-13
  • Supported by:
    The National Basic Research Program of China (973 Program)(2011CB311801);Zhengzhou Science and Technology Talents Program(131PLKRC644);Strategic Priority Research Program of the Chinese Academy of Sciences(XDA06010701);Young Scientist Program of Institute of Information Engineering CAS(118800808);CAS Key Deployment Project(Y6X0061105)

Abstract:

Moving target defense is a revolutionary technology which changes the situation of attack and defense.How to effectively achieve forwarding path mutation is one of the hotspot in this field.Since existing mechanisms are blindness and lack of constraints in the process of mutation,it is hard to maximize mutation defense benefit under the condition of good network quality of services.A novel of network moving target defense technique based on optimal forwarding path migration was proposed.Satisfiability modulo theory was adopted to formally describe the mutation constraints,so as to prevent transient problem.Optimization combination between routing path and mutation period was chosen by using optimal routing path generation method based on security capacity matrix so as to maximum defense benefit.Theoretical and experimental analysis show the defense cost and benefit in resisting passive sniffing attacks.The capability of achieving maximum defense benefit under the condition of ensuring network quality of service is proved.

Key words: moving target defense, forwarding path migration, satisfiability modulo theory, ransient problem, security capacity matrix, defense benefit maximization

CLC Number: 

No Suggested Reading articles found!