Search papers, labs, and topics across Lattice.
This paper introduces MTD-Playground, an evaluation framework designed to benchmark Software-Defined Networking (SDN)-enabled path randomization techniques for Moving Target Defense (MTD) against realistic multi-stage attack scenarios. By addressing the fragmented nature of existing evaluations, MTD-Playground employs a composite methodology that assesses deployment effectiveness and the trade-offs of mutation intervals, revealing that aggressive path randomization can significantly reduce attack success rates while enhancing network performance. The findings indicate that shorter mutation intervals not only disrupt attack progression but also improve throughput and reduce latency, making SDN-based PR-MTD a viable solution for enterprise cybersecurity.
Aggressive path randomization can cut attack success rates to as low as 4-20% while boosting network throughput by nearly 31%.
Moving Target Defense (MTD) has emerged as a proactive network cyber defense paradigm that increases attacker uncertainty through dynamic network reconfiguration techniques such as Software-Defined Networking (SDN)-enabled path randomization. However, existing evaluations remain fragmented due to inconsistent attacker assumptions, attack scenarios, and evaluation metrics, limiting reproducibility and deployment-oriented comparison. In this paper, we present MTD-Playground, an attacker-aware evaluation framework for benchmarking SDN-enabled path-randomization (PR) MTD techniques under realistic enterprise-style multi-stage attack scenarios. Beyond isolated security and performance metrics, MTD-Playground introduces a composite evaluation methodology for analyzing deployment effectiveness, mutation-interval trade-offs, and defender-attacker operational balance. Using periodic path randomization as a representative PR-MTD strategy, our evaluation shows that aggressive mutation intervals reduce attack success rates to 4-20% while increasing attack completion time to 160-311s across evaluated attack scenarios. At the same time, PR-MTD improves throughput by up to 30.9% and reduces internal-path latency without service interruption. Composite analysis further shows that shorter mutation intervals consistently achieve the highest deployment effectiveness and positive defender advantage. These results demonstrate that SDN-based PR-MTD can substantially disrupt multi-stage attack progression while remaining practically deployable in enterprise environments.