Moving Target Defense and Cyber Deception emerged in recent years as two key proactive cyber defense approaches, contrasting with the static nature of the traditional reactive cyber defense. The key insight behind these approaches is to impose an asymmetric disadvantage for the attacker by using deception and randomization techniques to create a dynamic attack surface. Moving Target Defense typically relies on system randomization and diversification, while Cyber Deception is based on decoy nodes and fake systems to deceive attackers. However, current Moving Target Defense techniques are complex to manage and can introduce high overheads, while Cyber Deception nodes are easily recognized and avoided by adversaries. This paper presents DOLOS, a novel architecture that unifies Cyber Deception and Moving Target Defense approaches. DOLOS is motivated by the insight that deceptive techniques are much more powerful when integrated into production systems rather than deployed alongside them. DOLOS combines typical Moving Target Defense techniques, such as randomization, diversity, and redundancy, with cyber deception and seamlessly integrates them into production systems through multiple layers of isolation. We extensively evaluate DOLOS against a wide range of attackers, ranging from automated malware to professional penetration testers, and show that DOLOS is highly effective in slowing down attacks and protecting the integrity of production systems. We also provide valuable insights and considerations for the future development of MTD techniques based on our findings.
翻译:近年来,移动目标防御与网络欺骗作为两种关键主动网络防御方法应运而生,与传统的被动式网络防御的静态特性形成鲜明对比。这些方法的核心思想是通过使用欺骗与随机化技术创建动态攻击面,从而对攻击者施加非对称劣势。移动目标防御通常依赖于系统随机化与多样化,而网络欺骗则基于诱饵节点和虚假系统来欺骗攻击者。然而,当前的移动目标防御技术管理复杂且可能引入高开销,而网络欺骗节点则容易被对手识别与规避。本文提出DOLOS,一种统一网络欺骗与移动目标防御方法的新型架构。DOLOS的动机源于如下洞察:欺骗技术在被整合到生产系统中而非部署于其旁侧时,效果会更为强大。DOLOS将典型的移动目标防御技术(如随机化、多样性和冗余)与网络欺骗相结合,并通过多层隔离将其无缝集成到生产系统中。我们针对从自动化恶意软件到专业渗透测试人员的广泛攻击者,对DOLOS进行了全面评估,结果表明DOLOS在减缓攻击速度和保护生产系统完整性方面具有高效性。此外,基于研究发现,我们还为移动目标防御技术的未来发展提供了有价值的见解与考量。