RL and Fingerprinting to Select Moving Target Defense Mechanisms for Zero-day Attacks in IoT

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Celdrán, Alberto Huertas, Sánchez, Pedro Miguel Sánchez, von der Assen, Jan, Schenk, Timo, Bovet, Gérôme, Pérez, Gregorio Martínez, Stiller, Burkhard
Format: Preprint
Published: 2022
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866917683777241088
author Celdrán, Alberto Huertas
Sánchez, Pedro Miguel Sánchez
von der Assen, Jan
Schenk, Timo
Bovet, Gérôme
Pérez, Gregorio Martínez
Stiller, Burkhard
author_facet Celdrán, Alberto Huertas
Sánchez, Pedro Miguel Sánchez
von der Assen, Jan
Schenk, Timo
Bovet, Gérôme
Pérez, Gregorio Martínez
Stiller, Burkhard
contents Cybercriminals are moving towards zero-day attacks affecting resource-constrained devices such as single-board computers (SBC). Assuming that perfect security is unrealistic, Moving Target Defense (MTD) is a promising approach to mitigate attacks by dynamically altering target attack surfaces. Still, selecting suitable MTD techniques for zero-day attacks is an open challenge. Reinforcement Learning (RL) could be an effective approach to optimize the MTD selection through trial and error, but the literature fails when i) evaluating the performance of RL and MTD solutions in real-world scenarios, ii) studying whether behavioral fingerprinting is suitable for representing SBC's states, and iii) calculating the consumption of resources in SBC. To improve these limitations, the work at hand proposes an online RL-based framework to learn the correct MTD mechanisms mitigating heterogeneous zero-day attacks in SBC. The framework considers behavioral fingerprinting to represent SBCs' states and RL to learn MTD techniques that mitigate each malicious state. It has been deployed on a real IoT crowdsensing scenario with a Raspberry Pi acting as a spectrum sensor. More in detail, the Raspberry Pi has been infected with different samples of command and control malware, rootkits, and ransomware to later select between four existing MTD techniques. A set of experiments demonstrated the suitability of the framework to learn proper MTD techniques mitigating all attacks (except a harmfulness rootkit) while consuming <1 MB of storage and utilizing <55% CPU and <80% RAM.
format Preprint
id arxiv_https___arxiv_org_abs_2212_14647
institution arXiv
publishDate 2022
record_format arxiv
spellingShingle RL and Fingerprinting to Select Moving Target Defense Mechanisms for Zero-day Attacks in IoT
Celdrán, Alberto Huertas
Sánchez, Pedro Miguel Sánchez
von der Assen, Jan
Schenk, Timo
Bovet, Gérôme
Pérez, Gregorio Martínez
Stiller, Burkhard
Cryptography and Security
Artificial Intelligence
Cybercriminals are moving towards zero-day attacks affecting resource-constrained devices such as single-board computers (SBC). Assuming that perfect security is unrealistic, Moving Target Defense (MTD) is a promising approach to mitigate attacks by dynamically altering target attack surfaces. Still, selecting suitable MTD techniques for zero-day attacks is an open challenge. Reinforcement Learning (RL) could be an effective approach to optimize the MTD selection through trial and error, but the literature fails when i) evaluating the performance of RL and MTD solutions in real-world scenarios, ii) studying whether behavioral fingerprinting is suitable for representing SBC's states, and iii) calculating the consumption of resources in SBC. To improve these limitations, the work at hand proposes an online RL-based framework to learn the correct MTD mechanisms mitigating heterogeneous zero-day attacks in SBC. The framework considers behavioral fingerprinting to represent SBCs' states and RL to learn MTD techniques that mitigate each malicious state. It has been deployed on a real IoT crowdsensing scenario with a Raspberry Pi acting as a spectrum sensor. More in detail, the Raspberry Pi has been infected with different samples of command and control malware, rootkits, and ransomware to later select between four existing MTD techniques. A set of experiments demonstrated the suitability of the framework to learn proper MTD techniques mitigating all attacks (except a harmfulness rootkit) while consuming <1 MB of storage and utilizing <55% CPU and <80% RAM.
title RL and Fingerprinting to Select Moving Target Defense Mechanisms for Zero-day Attacks in IoT
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2212.14647