Dynamic Application Rotation Environment for Moving Target Defense

Michael Thompson, Marilyne Mendolla, Michael Muggler, Moses Ike · 2016

Owing to the ubiquity of web applications in modern computing, the server software that delivers these applications is an attractive attack vector for would-be malicious actors in cyberspace. Recently, Moving Target Defense (MTD) strategies have grown in popularity in the computer security community because of their ability to enhance resilience and force attackers into uncharacteristic behavior. The MTD prototype discussed in this paper acts as a proactive defense strategy that offers increased protection against an attacker's ability to probe for and exploit vulnerable web server software. The testing shows that web server diversity in an MTD reduces the ability to exploit vulnerabilities in a web server, reduces impacts of successfully exploited vulnerabilities, and increases the resilience of the protected application.

Read the paper · More papers on PaperTik