MTD in Plain Sight: Hiding Network Behavior in Moving Target Defenses
Tina Moghaddam, Guowei Yang, Chandra Thapa, Seyit Ahmet Camtepe, Dong Seong Kim · 2024
Virtual IP shuffling moving target defenses (MTD) reduce the attacker’s success probability by imposing an unknown window in which they have to complete their attacks on a particular address. Previous work has shown that an attacker who knows the MTD window can greatly increase their attack success rate, and that enough information is leaked onto the network by an MTD trigger for this to be detectable by an attacker analyzing network traffic. In this work, we propose a way to hide when the MTD triggers by generating traffic that mimics the symptoms of the real MTD trigger in the network. These ‘mimic’ trigger events occur at different times in the MTD interval, thereby deceiving the attacker into detecting the wrong window size. In this paper, we 1) introduce the proposed hiding scheme, 2) discuss three methods of generating the mimic trigger events in our traffic, 3) implement and test one such scheme to show that it is effective at fooling the attacker, and 4) discuss the further challenges that need to be overcome to make this method a viable defense strategy.