Title : 
Using cyber maneuver to improve network resiliency
         
        
            Author : 
Beraud, Paul ; Cruz, Alen ; Hassell, Suzanne ; Meadows, Sonny
         
        
            Author_Institution : 
Network Centric Syst., Raytheon, Largo, FL, USA
         
        
        
        
        
        
            Abstract : 
The Net Maneuver Commander (NMC) is a research prototype cyber command and control (C2) system which constantly maneuvers network-based elements preemptively to improve network resiliency in a cyber compromised environment. Similar in concept to a frequency hopping radio, Network Maneuver Commander transparently and preemptively provides a moving target defense to evade attack. It utilizes randomization algorithms for maneuver destination selection, providing randomized synthetic diversity of hardware platforms, operating systems and network segments. Network Maneuver Commander also improves resiliency through random and pre-emptive application and platform reconstitution with check-pointing, reloading and resetting, and through the support of deception and containment of malware. The goals of the research were to increase the investment an attacker must make to succeed, increase the exposure of an attacker to detection as the attacker is forced to relearn the network and reestablish malware, increase the uncertainty of the success of the attack and to increase the overall survivability in the presence of attacks. This paper describes the Network Maneuver Commander architecture as well as the resiliency techniques provided including moving target defense, randomization, reconstitution, artificial diversity and deception. Lessons learned are also addressed.
         
        
            Keywords : 
command and control systems; frequency hop communication; military communication; telecommunication security; cyber compromised environment; cyber maneuver; detection attacker; frequency hopping radio; hardware platform; malware containment; maneuver destination selection; network maneuver commander; network resiliency; network-based element; operating system; preemptive application; randomization algorithm; randomized synthetic diversity; research prototype cyber command and control system; resiliency technique; Computer architecture; Hardware; IP networks; Malware; Operating systems; Virtual machine monitors; Artificial Diversity; Preemptive Maneuver; Randomization; Resiliency; Survivability;
         
        
        
        
            Conference_Titel : 
MILITARY COMMUNICATIONS CONFERENCE, 2011 - MILCOM 2011
         
        
            Conference_Location : 
Baltimore, MD
         
        
        
            Print_ISBN : 
978-1-4673-0079-7
         
        
        
            DOI : 
10.1109/MILCOM.2011.6127449