Skip to main navigation Skip to search Skip to main content

X-EDF: An Efficient Defensive Deception Framework against Reconnaissance Attacks

  • Zhihang Zhang
  • , Chenlin Huang*
  • , Yan Ding
  • , Jinzhu Kong
  • , Qing Liao
  • , Pan Dong
  • , Haifang Zhou
  • *Corresponding author for this work
  • National University of Defense Technology
  • KylinSoft Corporation
  • Harbin Institute of Technology Shenzhen

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Deception techniques are increasingly recognized as trans-formative in the realm of cyber defense. With the advent of sophisticated, large-scale scanning technologies such as ZMap, attackers can swiftly pinpoint active and vulnerable ports on edge nodes. Given the diversity of these nodes, a versatile security tool adaptable to various deployment environments is essential. Moreover, edge nodes often encounter performance constraints, necessitating a defense strategy that balances cost-effectiveness for defenders. In response to these challenges, we introduce the X-EDF: an eXpress Data Path (XDP)-based Efficient Defensive De-ception Framework. This framework facilitates an efficient and lightweight deceptive defense leveraging XDP technology. The X-EDF can efficiently respond to attackers' scanning requests with deceptive messages before these requests enter the protocol stack, thus achieving deception defense at a minimal cost. We have validated the effectiveness of our defense strategy through game-theoretic proofs and real-world network deployments.

Original languageEnglish
Title of host publicationProceedings - 2024 20th International Conference on Mobility, Sensing and Networking, MSN 2024
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages445-452
Number of pages8
ISBN (Electronic)9798331516024
DOIs
StatePublished - 2024
Externally publishedYes
Event20th International Conference on Mobility, Sensing and Networking, MSN 2024 - Harbin, China
Duration: 20 Dec 202422 Dec 2024

Publication series

NameProceedings - 2024 20th International Conference on Mobility, Sensing and Networking, MSN 2024

Conference

Conference20th International Conference on Mobility, Sensing and Networking, MSN 2024
Country/TerritoryChina
CityHarbin
Period20/12/2422/12/24

Keywords

  • cyber defense
  • deception techniques
  • edge computing
  • express data path (XDP)
  • game theory

Fingerprint

Dive into the research topics of 'X-EDF: An Efficient Defensive Deception Framework against Reconnaissance Attacks'. Together they form a unique fingerprint.

Cite this