A Software-Defined Intranet Dynamic Defense System

Chen Yang, Hongchao Hu, Cheng Guo-Zhen · 2018

The rise of Bring Your Own Device (BYOD) now poses new challenges to the traditional intranet, which used to deploy boundary-based defenses to guarantee internal security. The bringing of personal devices has threatened the internal security. Based on the idea of isolation and dynamic, this paper designs and implements a Software-defined Intranet Dynamic Defense System (SIDD) to harass cyber kill chain. Firstly, to solve the issue that network can be easily reconnoitered due to its static attributes, we allocate virtual IP address space for intranet terminals and implement the dynamic mapping between real IP addresses and virtual IP addresses to hide the real IP address. Secondly, we propose a software-defined dynamic defense architecture scheme, which manages to provide a general control of the intranet, including three core modules (e.g. DNS, virtual & real address assignment and virtual address maneuvering). Finally, we implement a dynamic defense system oriented to the production environment, based on the OpenDaylight controller. Our experiments indicate that this method can achieve a definable IP address, which frequency and space are maneuverable, thus it could significantly reduce the availability of network reconnaissance and increase the difficulties of attacker's realtime attack without affecting network applications.

Read the paper · More papers on PaperTik