MitiBox: camouflage and deception for network scan mitigation
Erwan Le Malécot · 2009
Reconnaissance, if successful, provides a definite tactical advantage in a battle and, as such, unsolicited computer network scans are often the precursors to more significant attacks against computer assets. In this paper, we introduce an original system whose purpose is to mitigate the benefits an attacker can expect from scanning a targeted network. In contrast to more traditional approaches, we propose to act a priori against scanning activity by continuously obfuscating the appearance of the targeted network through the combination of various simple mechanisms (i.e. random connection dropping and traffic forging). Moreover, we propose a method to immediately penalize hosts sending seemingly suspicious traffic to the targeted network while maintaining decent connectivity to cope with ”false positives”. 1