Implementing a "moving target" system to protect servers

Curtis R. Taylor, Craig A. Shue · 2011

On the Internet, attackers often compromise systems owned by other people and group these systems into a "botnet" to launch attacks automatically. Current methods to prevent such automated attacks are either are application-specific or use signatures that can that can miss some attacks. We take a different approach by making a key observation: while attackers have a low success rate, they often compensate for it by launching more attacks. To have high throughput, attackers take shortcuts and break protocols. We address these issues by implementing a system that can detect malicious activity and block attacks. We tested this system on a small network and found that it is effective, requires no administrative overhead, and has low performance overheads.

Read the paper · More papers on PaperTik