Title :
Effectiveness of Port Hopping as a Moving Target Defense
Author :
Yue-Bin Luo ; Bao-Sheng Wang ; Gui-Lin Cai
Author_Institution :
Coll. of Comput., Nat. Univ. of Defense Technol., Changsha, China
Abstract :
Port hopping is a typical moving target defense, which constantly changes service port number to thwart reconnaissance attack. It is effective in hiding service identities and confusing potential attackers, but it is still unknown how effective port hopping is and under what circumstances it is a viable proactive defense because the existed works are limited and they usually discuss only a few parameters and give some empirical studies. This paper introduces urn model and quantifies the likelihood of attacker success in terms of the port pool size, number of probes, number of vulnerable services, and hopping frequency. Theoretical analysis shows that port hopping is an effective and promising proactive defense technology in thwarting network attacks.
Keywords :
security of data; attacker success likelihood; moving target defense; network attacks; port hopping; proactive defense technology; reconnaissance attack; service identity hiding; urn model; Analytical models; Computers; Ports (Computers); Probes; Reconnaissance; Servers; moving target defense; port hopping; proactive defense; urn model;
Conference_Titel :
Security Technology (SecTech), 2014 7th International Conference on
Conference_Location :
Haikou
Print_ISBN :
978-1-4799-7775-8
DOI :
10.1109/SecTech.2014.9