Moving-Target Single Packet Authorization to Protect Network Service from Sniffing

Pierre-Loup Guerrieri, Fériel Bouakkaz, Toufik Ahmed · 2025

This paper presents a novel enhancement to Single Packet Authorization (SPA), namely Moving-target SPA (mSPA), that strengthens network security by leveraging moving target defense to enable dynamic port management and service concealment in softwarized networks. Traditional techniques are limited in their ability to mask services effectively, leaving them vulnerable to attacks such as port scanning, sniffing, and traffic analysis. Our solution addresses these limitations by introducing a SPA response validation to ensure that single packet authorization is correctly processed and the access port, managed dynamically, is only granted to legitimate users, thereby preventing unauthorized access and enhancing overall security. This strategy aligns with modern security paradigms, such as Zero Trust Architecture, and addresses the need for scalable, lightweight solutions in IoT environments, where dynamic and resource-constrained systems face significant security challenges. We validate the mSPA approach using a real experiment. The results suggest that our approach is scalable and effective in masking and protecting network services by minimizing the visibility of services and reducing the attack surface.

Read the paper · More papers on PaperTik