A SPL Framework for Adaptive Deception-based Defense

dc.contributor.authorDe Faveri, Cristiano
dc.contributor.authorMoreira, Ana
dc.date.accessioned2017-12-28T02:18:07Z
dc.date.available2017-12-28T02:18:07Z
dc.date.issued2018-01-03
dc.description.abstractIn cyber defense, integrated deception mechanisms have been proposed as part of the system operation to enhance security by planting fake resources. The objective is to entice attackers and confuse them in determining the legitimacy of those resources. Although several strategies exist to implement deception in a software system, developing and integrating such solutions are primarily made in an ad-hoc fashion. This hinders reuse and does not consider the operation life cycle management. Additionally, support for adaptive deception is not considered. To alleviate these problems, we propose a framework based on software product lines and aspect-oriented techniques to generate adaptive deception-based defense strategies. We illustrate the feasibility of our approach with an example from the web applications domain, by integrating honeywords into an authentication mechanism to mitigate offline password cracking attacks.
dc.format.extent10 pages
dc.identifier.doi10.24251/HICSS.2018.691
dc.identifier.isbn978-0-9981331-1-9
dc.identifier.urihttp://hdl.handle.net/10125/50580
dc.language.isoeng
dc.relation.ispartofProceedings of the 51st Hawaii International Conference on System Sciences
dc.rightsAttribution-NonCommercial-NoDerivatives 4.0 International
dc.rights.urihttps://creativecommons.org/licenses/by-nc-nd/4.0/
dc.subjectCyber Threat Intelligence and Analytics
dc.subjectSecurity, Cyber Deception, Software Product Line, Aspect-Oriented
dc.titleA SPL Framework for Adaptive Deception-based Defense
dc.typeConference Paper
dc.type.dcmiText

Files

Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
paper0693.pdf
Size:
926.31 KB
Format:
Adobe Portable Document Format