erseco/moving_target_defense

Focus for the new Master's thesis

Opened this issue · 1 comments

JJ commented

The methodology can be more or less the same

  • Use industry-standard scores to assess the security of a certain installation.
  • Improve configuration via evolutionary (or other) algorithms, focusing on certain services or overall configuration.

But once that's said and done, we need to

  • See if we focus on security, or also speed, for a multimodal optimization algorithm.
  • Focus on server hardening or other services: there's been a lot of work on SDN, for instance.
  • Even within servers, expand the possible configurations (use several different web servers, for instance), or more services (ssh servers, others).
JJ commented

Please comment here.