Software Deception Steering through Version Emulation

dc.contributor.authorAraujo, Frederico
dc.contributor.authorSengupta, Sailik
dc.contributor.authorJang, Jiyong
dc.contributor.authorDoupé, Adam
dc.contributor.authorHamlen, Kevin
dc.contributor.authorKambhampati, Subbarao
dc.date.accessioned2020-12-24T19:23:48Z
dc.date.available2020-12-24T19:23:48Z
dc.date.issued2021-01-05
dc.description.abstractDetermined cyber adversaries often strategize their attacks by carefully selecting high-value target machines that host insecure (e.g., unpatched) legacy software. In this paper, we propose a moving-target approach to thwart and countersurveil such adversaries, wherein live (non-decoy) enterprise software services are automatically modified to deceptively emulate vulnerable legacy versions that entice attackers. A game-theoretic framework chooses which emulated software stacks, versions, configurations, and vulnerabilities yield the best defensive payoffs and most useful threat data given a specific attack model. The results show that effective movement strategies can be computed to account for pragmatic aspects of deception, such as the utility of various intelligence-gathering actions, impact of vulnerabilities, performance costs of patch deployment, complexity of exploits, and attacker profile.
dc.format.extent10 pages
dc.identifier.doihttps://doi.org/10.24251/HICSS.2021.243
dc.identifier.isbn978-0-9981331-4-0
dc.identifier.urihttp://hdl.handle.net/10125/70856
dc.language.isoEnglish
dc.relation.ispartofProceedings of the 54th Hawaii International Conference on System Sciences
dc.rightsAttribution-NonCommercial-NoDerivatives 4.0 International
dc.rights.urihttps://creativecommons.org/licenses/by-nc-nd/4.0/
dc.subjectCyber Deception and Cyber Psychology for Defense
dc.subjectagility
dc.subjectcyberdeception
dc.subjectgame theory
dc.subjectsecurity engineering
dc.subjectsoftware security
dc.titleSoftware Deception Steering through Version Emulation
prism.startingpage1988

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
0196.pdf
Size:
770.71 KB
Format:
Adobe Portable Document Format