OSINT-Based LPC-MTD and HS-Decoy for Organizational Defensive Deception

This study aimed to alleviate the theoretical limitations of existing moving target defense (MTD) and decoy concepts and improve the efficiency of defensive deception technology within an organization. We present the concept of an open-source intelligence (OSINT)-based hierarchical social engineerin...

Full description

Bibliographic Details
Main Authors: Sang Seo, Dohoon Kim
Format: Article
Language:English
Published: MDPI AG 2021-04-01
Series:Applied Sciences
Subjects:
Online Access:https://www.mdpi.com/2076-3417/11/8/3402
id doaj-6cd2a309b3694876b851c39371fa0fc8
record_format Article
spelling doaj-6cd2a309b3694876b851c39371fa0fc82021-04-10T23:01:55ZengMDPI AGApplied Sciences2076-34172021-04-01113402340210.3390/app11083402OSINT-Based LPC-MTD and HS-Decoy for Organizational Defensive DeceptionSang Seo0Dohoon Kim1Department of Computer Science, Kyonggi University, Suwon-si, Gyeonggi-do 16227, KoreaDepartment of Computer Science, Kyonggi University, Suwon-si, Gyeonggi-do 16227, KoreaThis study aimed to alleviate the theoretical limitations of existing moving target defense (MTD) and decoy concepts and improve the efficiency of defensive deception technology within an organization. We present the concept of an open-source intelligence (OSINT)-based hierarchical social engineering decoy (HS-Decoy) strategy while considering the actual fingerprint of each organization. In addition, we propose a loosely proactive control-based MTD strategy that is based on the intended competitive exposure of OSINT between defenders and attackers. Existing MTDs and decoys are biased toward proactive prevention, in that they only perform structural mutation-based attack avoidance or induce static traps. They also have practical limitations, e.g., they do not consider security characterization of each organizational social engineering attack and related utilization plans, no quantitative deception modeling is performed for the attenuation of the attack surface through exposure to OSINT, and there is no operational plan for optimal MTD and decoy application within the organization. Through the applied deception concepts proposed here, the total attack efficiency was reduced by 287% compared to the existing MTD and decoys, while the artificial deception efficiency dominated by defenders was improved by 382%. In addition, the increase rate of deception overhead was also reduced by 174%, and an optimized deceptive trade-off was also presented. In order to enable an organization to utilize the OSINT concept, statistical error reduction, and MTD mutation cycle-based deceptive selectivity, it was introduced as a loose adaptive mutation rather than a preferential avoidance strategy, and an organization-specific optimization direction was introduced through a combination of HS-Decoy and LPC-MTD. In the future, in order to improve the operational reliability of the HS-Decoy and LPC-MTD-based combined model and standardize threat information for each organization, we intend to advance it into an international standard-based complex architecture and characterize it as game theory.https://www.mdpi.com/2076-3417/11/8/3402cyber deceptionmoving target defensedecoyopen-source intelligencesocial engineering
collection DOAJ
language English
format Article
sources DOAJ
author Sang Seo
Dohoon Kim
spellingShingle Sang Seo
Dohoon Kim
OSINT-Based LPC-MTD and HS-Decoy for Organizational Defensive Deception
Applied Sciences
cyber deception
moving target defense
decoy
open-source intelligence
social engineering
author_facet Sang Seo
Dohoon Kim
author_sort Sang Seo
title OSINT-Based LPC-MTD and HS-Decoy for Organizational Defensive Deception
title_short OSINT-Based LPC-MTD and HS-Decoy for Organizational Defensive Deception
title_full OSINT-Based LPC-MTD and HS-Decoy for Organizational Defensive Deception
title_fullStr OSINT-Based LPC-MTD and HS-Decoy for Organizational Defensive Deception
title_full_unstemmed OSINT-Based LPC-MTD and HS-Decoy for Organizational Defensive Deception
title_sort osint-based lpc-mtd and hs-decoy for organizational defensive deception
publisher MDPI AG
series Applied Sciences
issn 2076-3417
publishDate 2021-04-01
description This study aimed to alleviate the theoretical limitations of existing moving target defense (MTD) and decoy concepts and improve the efficiency of defensive deception technology within an organization. We present the concept of an open-source intelligence (OSINT)-based hierarchical social engineering decoy (HS-Decoy) strategy while considering the actual fingerprint of each organization. In addition, we propose a loosely proactive control-based MTD strategy that is based on the intended competitive exposure of OSINT between defenders and attackers. Existing MTDs and decoys are biased toward proactive prevention, in that they only perform structural mutation-based attack avoidance or induce static traps. They also have practical limitations, e.g., they do not consider security characterization of each organizational social engineering attack and related utilization plans, no quantitative deception modeling is performed for the attenuation of the attack surface through exposure to OSINT, and there is no operational plan for optimal MTD and decoy application within the organization. Through the applied deception concepts proposed here, the total attack efficiency was reduced by 287% compared to the existing MTD and decoys, while the artificial deception efficiency dominated by defenders was improved by 382%. In addition, the increase rate of deception overhead was also reduced by 174%, and an optimized deceptive trade-off was also presented. In order to enable an organization to utilize the OSINT concept, statistical error reduction, and MTD mutation cycle-based deceptive selectivity, it was introduced as a loose adaptive mutation rather than a preferential avoidance strategy, and an organization-specific optimization direction was introduced through a combination of HS-Decoy and LPC-MTD. In the future, in order to improve the operational reliability of the HS-Decoy and LPC-MTD-based combined model and standardize threat information for each organization, we intend to advance it into an international standard-based complex architecture and characterize it as game theory.
topic cyber deception
moving target defense
decoy
open-source intelligence
social engineering
url https://www.mdpi.com/2076-3417/11/8/3402
work_keys_str_mv AT sangseo osintbasedlpcmtdandhsdecoyfororganizationaldefensivedeception
AT dohoonkim osintbasedlpcmtdandhsdecoyfororganizationaldefensivedeception
_version_ 1721531723169136640