Multi-dimensional Host Identity Anonymization for Defeating Skilled Attackers

Multi-dimensional Host Identity Anonymization for Defeating Skilled Attackers
复制标题

多维主机身份匿名化,击败熟练攻击者

DOI:
--
复制
发表时间:
2016
期刊:
MTD@CCS
影响因子:
--
通讯作者:
Qi Duan
Qi Duan
中科院分区:
--
文献类型:
--
作者:
J. H. Jafarian;Amirreza Niakanlahiji;E. Al;Qi Duan

文献摘要

被引文献

相似文献

虽然现有的基于主动的范例(如地址突变)在减缓天真攻击者的侦察方面是有效的,但它们对熟练的人类攻击者无效。在本文中,我们分析表明,只有通过集成五个防御维度才能实现击败熟练的人类攻击者的侦察目标:(1)改变主机地址,(2)改变主机指纹,(3)匿名主机指纹,(4)部署具有上下文感知指纹的高保真蜜罐,以及(5)在这些蜜罐上部署上下文感知内容。使用一类新的蜜罐,被称为代理蜜罐(高互动蜜罐与可定制的指纹),我们提出了一个积极的防御模型,称为(HIDE),不断变异的地址和指纹的网络主机和代理蜜罐的方式,最大限度地匿名的网络主机的身份。其目的是通过不让即使是熟练的攻击者重复使用在先前扫描中发现的主机属性(包括其地址和指纹)来再次识别该主机,从而使主机随着时间的推移而不可追踪。突变是通过正式定义和建模的问题。通过与一组白帽黑客进行红队评估,我们评估了我们的五维防御模型,并将其有效性与替代方案和竞争方案进行了比较。这些实验以及我们的分析评估表明,随着时间的推移,通过匿名化主机/蜜罐的所有识别属性,HIDE能够显着复杂化侦察,即使是高度熟练的人类攻击者。
While existing proactive-based paradigms such as address mutation are effective in slowing down reconnaissance by naive attackers, they are ineffective against skilled human attackers. In this paper, we analytically show that the goal of defeating reconnaissance by skilled human attackers is only achievable by an integration of five defensive dimensions: (1) mutating host addresses, (2) mutating host fingerprints, (3) anonymizing host fingerprints, (4) deploying high-fidelity honeypots with context-aware fingerprints, and (5) deploying context-aware content on those honeypots. Using a novel class of honeypots, referred to as proxy honeypots (high-interaction honeypots with customizable fingerprints), we propose a proactive defense model, called (HIDE), that constantly mutates addresses and fingerprints of network hosts and proxy honeypots in a manner that maximally anonymizes identity of network hosts. The objective is to make a host untraceable over time by not letting even skilled attackers reuse discovered attributes of a host in previous scanning, including its addresses and fingerprint, to identify that host again. The mutations are generated through formal definition and modeling the problem. Using a red teaming evaluation with a group of white-hat hackers, we evaluated our five-dimensional defense model and compared its effectiveness with alternative and competing scenarios. These experiments as well as our analytical evaluation show that by anonymizing all identifying attributes of a host/honeypot over time, HIDE is able to significantly complicate reconnaissance, even for highly skilled human attackers.