Modeling and Analysis of Integrated Proactive Defense Mechanisms for Internet-of-Things
Mengmeng Ge, Jin-Hee Cho, Bilal Ishfaq, and Dong Seong Kim

TL;DR
This paper proposes an integrated proactive defense mechanism for IoT networks combining cyberdeception and moving target defense, validated through a graphical security model and genetic algorithm-based topology shuffling.
Contribution
It introduces a novel integrated proactive defense approach for IoT, leveraging cyberdeception, MTD, and genetic algorithms for optimal network topology shuffling.
Findings
GA-based shuffling outperforms random schemes in reducing attack paths.
Tradeoff observed between system lifetime and defense cost.
Adaptive shuffling balances security and cost effectively.
Abstract
As a solution to protect and defend a system against inside attacks, many intrusion detection systems (IDSs) have been developed to identify and react to them for protecting a system. However, the core idea of an IDS is a reactive mechanism in nature even though it detects intrusions which have already been in the system. Hence, the reactive mechanisms would be way behind and not effective for the actions taken by agile and smart attackers. Due to the inherent limitation of an IDS with the reactive nature, intrusion prevention systems (IPSs) have been developed to thwart potential attackers and/or mitigate the impact of the intrusions before they penetrate into the system. In this chapter, we introduce an integrated defense mechanism to achieve intrusion prevention in a software-defined Internet-of-Things (IoT) network by leveraging the technologies of cyberdeception (i.e., a decoy…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsNetwork Security and Intrusion Detection · Information and Cyber Security · Advanced Malware Detection Techniques
