Title :
Reducing Attack Surface with VM-Based Phantom Server
Author :
Li Wang ; Zhan Wang ; Kun Sun ; Jajodia, Sushil
Author_Institution :
Center for Secure Inf. Syst., George Mason Univ., Fairfax, VA, USA
Abstract :
Online servers are the primary target of the attack due to their high exposure of various attack surfaces. In this paper, we present a phantom server architecture to reduce the attack surfaces of online servers by separating the protected content from the interface that may be accessed by both regular users and potential attackers. We call the server running the interfaces as Portal Server, and the server providing the protected services as Phantom Server. Only authenticated clients are able to get services from the phantom server. The phantom server architecture reduces the attack surfaces by hiding the phantom server from being detected by the attackers. Moreover, even if the portal server is compromised, the attacker still cannot locate the phantom server and perform further attacks. Our system architecture can be deployed without any hardware or software changes on the legacy servers. We implement a virtual machine (VM) based on phantom server prototype to protect online web and database servers. The experimental results show a low overhead on our phantom server architecture.
Keywords :
computer network security; network servers; virtual machines; attack surface reduction; authenticated clients; database servers; legacy servers; online Web; online servers; phantom server architecture; portal server; virtual machine; Computer architecture; Databases; IP networks; Phantoms; Portals; Web servers;
Conference_Titel :
Military Communications Conference, MILCOM 2013 - 2013 IEEE
Conference_Location :
San Diego, CA
DOI :
10.1109/MILCOM.2013.242