Every Time Can Be Different: A Data Dynamic Protection Method Based on Moving Target Defense.

Zhimin Tang,Duohe Ma,Xiaoyan Sun,Kai Chen,Liming Wang,Junye Jiang
DOI: https://doi.org/10.1109/iscc58397.2023.10218253
2023-01-01
Abstract:Traditional defense methods are hard to change the inherent vulnerabilities of static data storage, single data access, and deterministic data content, leading to frequent data leakage incidents. Moving target defense (MTD) techniques can increase data diversity and unpredictability by dynamically shifting the data attack surface. However, in the existing methods, the data lacks sufficient dynamics due to insufficient shifting space and shifting frequency of attack surface, and legitimate users are inevitably greatly affected. This study proposes a data MTD method that the data changes dynamically based on real-time multi-source user access information. Through the multidimensional user stratification mechanism, we establish a novel dynamic data model that uses the combination of random deception strategies to convert metadata properties and content of data based on the user risk levels, while data remains unchanged for legitimate users. Multiple sets of experiments demonstrate the effectiveness and low consumption of our data dynamic defense approach.
What problem does this paper attempt to address?