Modeling network based moving target defense impacts through simulation in Ns-3

Modeling network based moving target defense impacts through simulation in Ns-3
复制标题

通过 NS-3 中的模拟对基于网络的移动目标防御影响进行建模

DOI:
--
复制
发表时间:
2016
期刊:
IEEE Military Communications Conference
影响因子:
--
通讯作者:
J. Tront
J. Tront
中科院分区:
--
文献类型:
--
作者:
Franki Yeung;Peter K. Cho;Christopher Morrell;R. Marchany;J. Tront

文献摘要

被引文献

相似文献

基于网络的移动目标防御系统是计算机安全和隐私领域的宝贵补充。正在进行的研究试图通过向移动目标IPv6防御(MT6D)系统添加客户端/服务器功能来推动基于网络的移动目标防御的边界。虽然这一附加功能提供了许多好处,但重要的是要充分了解实施MT6D服务器对网络的影响,因为根据定义,MT6D服务器会大大增加网段上的管理流量。IPv6依赖邻居发现协议(NDP)来实现所有网络管理功能,包括发现当前活动的地址。在主机可以开始使用所述地址之前,绑定的每个地址需要交换多个NDP消息。当MT6D服务器需要将大量IPv6地址绑定到单个接口时,由于生成的NDP流量的数量,可能会对网络产生一些负面影响。这项工作试图通过使用ns-3仿真和现场实验来量化NDP流量生成对网络的具体影响。
Network-based moving target defense systems are a valuable addition to the world of computer security and privacy. Ongoing research attempts to push the boundaries of network-based moving target defenses by adding client/server functionality to the Moving Target IPv6 Defense (MT6D) system. While this additional functionality provides a great many benefits, it is important to fully understand the impact to the network of implementing an MT6D server, which by definition greatly increases the amount of management traffic on a network segment. IPv6 relies on the Neighbor Discovery Protocol (NDP) for all network management functions, including the discovery of currently active addresses. Each address that is bound requires a number of NDP messages to be exchanged before a host can begin using said address. When an MT6D server requires the binding of a large number of IPv6 addresses to a single interface, there is likely to be some negative impact to the network due to the amount of NDP traffic that is generated. This work attempts to quantify the specific impact to the network from NDP traffic generation through the use of ns-3 simulations and live experiments.