Design and implementation of a novel enterprise network defense system bymaneuveringmulti-dimensional network properties | Frontiers of Information Technology & Electronic Engineering Skip to main content
Log in

Design and implementation of a novel enterprise network defense system bymaneuveringmulti-dimensional network properties

  • Published:
Frontiers of Information Technology & Electronic Engineering Aims and scope Submit manuscript

Abstract

Although the perimeter security model works well enough when all internal hosts are credible, it is becoming increasingly difficult to enforce as companies adopt mobile and cloud technologies, i.e., the rise of bring your own device (BYOD). It is observed that advanced targeted cyber-attacks usually follow a cyber kill chain; for instance, advanced targeted attacks often rely on network scanning techniques to gather information about potential targets. In response to this attack method, we propose a novel approach, i.e., an “isolating and dynamic” cyber defense, which cuts these potential chains to reduce the cumulative availability of the gathered information. First, we build a zero-trust network environment through network isolation, and then multiple network properties are maneuvered so that the host characteristics and locations needed to identify vulnerabilities cannot be located. Second, we propose a software-defined proactive cyber defense solution (SPD) for enterprise networks and design a general framework to strategically maneuver the IP address, network port, domain name, and path, while limiting the performance impact on the benign network user. Third, we implement our SPD proof-of-concept system over a software-defined network controller (OpenDaylight). Finally, we build an experimental platform to verify the system’s ability to prevent scanning, eavesdropping, and denial-of-service attacks. The results suggest that our system can significantly reduce the availability of network reconnaissance scan information, block network eavesdropping, and sharply increase the cost of cyber-attacks.

This is a preview of subscription content, log in via an institution to check access.

Access this article

Subscribe and save

Springer+ Basic
¥17,985 /Month
  • Get 10 units per month
  • Download Article/Chapter or eBook
  • 1 Unit = 1 Article or 1 Chapter
  • Cancel anytime
Subscribe now

Buy Now

Price includes VAT (Japan)

Instant access to the full article PDF.

Similar content being viewed by others

References

Download references

Author information

Authors and Affiliations

Authors

Corresponding author

Correspondence to Hong-chao Hu.

Additional information

Project supported by the Information Engineering University Emerging Direction Cultivation Fund, China (No. 2016610708), the Science and Technology Research Project of Henan, China (No. 172102210615), the National Natural Science Foundation of China (Nos. 61521003 and 61602509), and the National Key Research and Development Program of China (Nos. 2016YFB0800100 and 2016YFB0800101)

Rights and permissions

Reprints and permissions

About this article

Check for updates. Verify currency and authenticity via CrossMark

Cite this article

Chen, Y., Hu, Hc. & Cheng, Gz. Design and implementation of a novel enterprise network defense system bymaneuveringmulti-dimensional network properties. Frontiers Inf Technol Electronic Eng 20, 238–252 (2019). https://doi.org/10.1631/FITEE.1800516

Download citation

  • Received:

  • Revised:

  • Published:

  • Issue Date:

  • DOI: https://doi.org/10.1631/FITEE.1800516

Key words

CLC number

Navigation