DocumentCode :
2975679
Title :
Using cyber maneuver to improve network resiliency
Author :
Beraud, Paul ; Cruz, Alen ; Hassell, Suzanne ; Meadows, Sonny
Author_Institution :
Network Centric Syst., Raytheon, Largo, FL, USA
fYear :
2011
fDate :
7-10 Nov. 2011
Firstpage :
1121
Lastpage :
1126
Abstract :
The Net Maneuver Commander (NMC) is a research prototype cyber command and control (C2) system which constantly maneuvers network-based elements preemptively to improve network resiliency in a cyber compromised environment. Similar in concept to a frequency hopping radio, Network Maneuver Commander transparently and preemptively provides a moving target defense to evade attack. It utilizes randomization algorithms for maneuver destination selection, providing randomized synthetic diversity of hardware platforms, operating systems and network segments. Network Maneuver Commander also improves resiliency through random and pre-emptive application and platform reconstitution with check-pointing, reloading and resetting, and through the support of deception and containment of malware. The goals of the research were to increase the investment an attacker must make to succeed, increase the exposure of an attacker to detection as the attacker is forced to relearn the network and reestablish malware, increase the uncertainty of the success of the attack and to increase the overall survivability in the presence of attacks. This paper describes the Network Maneuver Commander architecture as well as the resiliency techniques provided including moving target defense, randomization, reconstitution, artificial diversity and deception. Lessons learned are also addressed.
Keywords :
command and control systems; frequency hop communication; military communication; telecommunication security; cyber compromised environment; cyber maneuver; detection attacker; frequency hopping radio; hardware platform; malware containment; maneuver destination selection; network maneuver commander; network resiliency; network-based element; operating system; preemptive application; randomization algorithm; randomized synthetic diversity; research prototype cyber command and control system; resiliency technique; Computer architecture; Hardware; IP networks; Malware; Operating systems; Virtual machine monitors; Artificial Diversity; Preemptive Maneuver; Randomization; Resiliency; Survivability;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
MILITARY COMMUNICATIONS CONFERENCE, 2011 - MILCOM 2011
Conference_Location :
Baltimore, MD
ISSN :
2155-7578
Print_ISBN :
978-1-4673-0079-7
Type :
conf
DOI :
10.1109/MILCOM.2011.6127449
Filename :
6127449
Link To Document :
بازگشت