Evaluating the Effectiveness of IP Hopping via an Address Routing Gateway
Ryan A . Morehart · 2013
AFIT-ENG-13-M-35 This thesis explores the viability of using Internet Protocol (IP) address hopping in front of a network as a defensive measure. Network address space randomization techniques theoretically provide protection to a network by appearing to randomly change the addresses of hosts inside, presenting a challenge to an intruder attempting to break in and map the network. This research presents a custom gateway-based IP hopping solution called Address Routing Gateway (ARG) that combines previous work in this area. ARG works as a transparent gateway in front of a network, requiring no changes to the hosts inside or out. Each ARG gateway is configured with a small amount of knowledge on one or more other gateways, allowing them to connect and pass fully encrypted and authenticated traffic amongst themselves. Connections to non-ARG networks or hosts are handled gracefully, allowing long-lived connections to exist without terminating them during IP address changes. This thesis tests the overall stability of ARG, the accuracy of its classifications, the maximum throughput it can support, and the maximum rate at which