Publishing Service

Polishing & Checking

Frontiers of Information Technology & Electronic Engineering

ISSN 2095-9184 (print), ISSN 2095-9230 (online)

Moving target defense: state of the art and characteristics

Abstract: Moving target defense (MTD) has emerged as one of the game-changing themes to alter the asymmetric situation between attacks and defenses in cyber-security. Numerous related works involving several facets of MTD have been published. However, comprehensive analyses and research on MTD are still absent. In this paper, we present a survey on MTD technologies to scientifically and systematically introduce, categorize, and summarize the existing research works in this field. First, a new security model is introduced to describe the changes in the traditional defense paradigm and security model caused by the introduction of MTD. A function-and-movement model is provided to give a panoramic overview on different perspectives for understanding the existing MTD research works. Then a systematic interpretation of published literature is presented to describe the state of the art of the three main areas in the MTD field, namely, MTD theory, MTD strategy, and MTD evaluation. Specifically, in the area of MTD strategy, the common characteristics shared by the MTD strategies to improve system security and effectiveness are identified and extrapolated. Thereafter, the methods to implement these characteristics are concluded. Moreover, the MTD strategies are classified into three types according to their specific goals, and the necessary and sufficient conditions of each type to create effective MTD strategies are then summarized, which are typically one or more of the aforementioned characteristics. Finally, we provide a number of observations for the future direction in this field, which can be helpful for subsequent researchers.

Key words: Moving target defense, Security model, Function-and-movement model, Characteristics

Chinese Summary  <46> 移动目标防御:现状及特征

概要:易攻难守是当前网络安全研究面临的核心问题,而移动目标防御(Moving target defense, MTD)为解决这一问题提供了一种全新思路。当前已有涉及MTD多个方面的大量研究被提出。然而,目前尚缺乏对MTD的综合性分析和研究。本文的主要目的是对该研究领域的已有成果进行系统性的介绍、分类和总结。我们首先提出了一个新的安全模型来描述MTD的引入对传统防御模式和安全模型的影响,同时还提出了一个功能和移动模型,为从不同方面理解已有的MTD研究提供了一个全新的视角。然后,我们分别对MTD的三个子领域(MTD机理研究、MTD策略研究、MTD评估研究)中的大量文献进行详细描述,以展示MTD领域的发展现状。尤其是在MTD策略子领域,我们对一些能保证这些策略正常有效运行的共有特征进行了识别和提取,并总结了创建这些特征的方式和方法。我们还依据MTD策略的特定目标将已有研究分为三种类型,并总结了创建每种类型策略的充要条件,这些充要条件是前面所总结的特征中的一个或多个。最后,我们对该领域的未来研究方向进行了探讨。

关键词组:移动目标防御;安全模型;功能和移动模型;特征


Share this article to: More

Go to Contents

References:

<Show All>

Open peer comments: Debate/Discuss/Question/Opinion

<1>

Please provide your name, email address and a comment





DOI:

10.1631/FITEE.1601321

CLC number:

TP393

Download Full Text:

Click Here

Downloaded:

3716

Download summary:

<Click Here> 

Downloaded:

1774

Clicked:

5900

Cited:

1

On-line Access:

2016-11-07

Received:

2016-06-11

Revision Accepted:

2016-08-14

Crosschecked:

2016-10-09

Journal of Zhejiang University-SCIENCE, 38 Zheda Road, Hangzhou 310027, China
Tel: +86-571-87952276; Fax: +86-571-87952331; E-mail: jzus@zju.edu.cn
Copyright © 2000~ Journal of Zhejiang University-SCIENCE