Toward Smart Moving Target Defense for Linux Container Resiliency

Mohamed Azab,Bassem Mokhtar,Amr S. Abed,Mohamed Eltoweissy
DOI: https://doi.org/10.48550/arXiv.1611.03065
2016-11-09
Cryptography and Security
Abstract:This paper presents ESCAPE, an informed moving target defense mechanism for cloud containers. ESCAPE models the interaction between attackers and their target containers as a "predator searching for a prey" search game. Live migration of Linux-containers (prey) is used to avoid attacks (predator) and failures. The entire process is guided by a novel host-based behavior-monitoring system that seamlessly monitors containers for indications of intrusions and attacks. To evaluate ESCAPE effectiveness, we simulated the attack avoidance process based on a mathematical model mimicking the prey-vs-predator search game. Simulation results show high container survival probabilities with minimal added overhead.
What problem does this paper attempt to address?