Proactive Defense for Internet-of-Things: Integrating Moving Target Defense with Cyberdeception
Mengmeng Ge, Jin-Hee Cho, Dong Seong Kim, Gaurav Dixit, Ing-Ray Chen

TL;DR
This paper presents an integrated defense approach combining cyberdeception and moving target defense to protect resource-constrained IoT devices, enhancing security by prolonging system lifetime and increasing attack complexity.
Contribution
It introduces a novel combined defense technique for IoT networks, with strategies for optimal network topology shuffling to achieve multiple security and performance goals.
Findings
Prolongs system lifetime compared to non-defensive networks.
Increases attack complexity for critical node compromise.
Maintains high service availability under attack.
Abstract
Resource constrained Internet-of-Things (IoT) devices are highly likely to be compromised by attackers because strong security protections may not be suitable to be deployed. This requires an alternative approach to protect vulnerable components in IoT networks. In this paper, we propose an integrated defense technique to achieve intrusion prevention by leveraging cyberdeception (i.e., a decoy system) and moving target defense (i.e., network topology shuffling). We verify the effectiveness and efficiency of our proposed technique analytically based on a graphical security model in a software defined networking (SDN)-based IoT network. We develop four strategies (i.e., fixed/random and adaptive/hybrid) to address "when" to perform network topology shuffling and three strategies (i.e., genetic algorithm/decoy attack path-based optimization/random) to address "how" to perform network…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInformation and Cyber Security · Network Security and Intrusion Detection · Advanced Malware Detection Techniques
