{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,14]],"date-time":"2026-05-14T19:58:16Z","timestamp":1778788696496,"version":"3.51.4"},"reference-count":39,"publisher":"Springer Science and Business Media LLC","issue":"6","license":[{"start":{"date-parts":[[2023,1,6]],"date-time":"2023-01-06T00:00:00Z","timestamp":1672963200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2023,1,6]],"date-time":"2023-01-06T00:00:00Z","timestamp":1672963200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Wireless Netw"],"published-print":{"date-parts":[[2024,8]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>Industrial Control Systems are used in a wide variety of industrial facilities, including critical infrastructures, becoming the main target of multiple security attacks. A malicious and successful attack against these infrastructures could cause serious economic and environmental consequences, including the loss of human lives. Static networks configurations and topologies, which characterize Industrial Control Systems, represent an advantage for attackers, allowing them to scan for vulnerable devices or services before carrying out the attack. Identifying active devices and services is often the first step for many attacks. This paper presents a proactive network reconnaissance defense mechanism based on the temporal randomization of network IP addresses, MAC addresses and port numbers. The obtained information distortion minimizes the knowledge acquired by the attackers, hindering any attack that relies on network addressing. The temporal randomization of network attributes is performed in an adaptive way, minimizing the overhead introduced in the network and avoiding any error and latency in communications. The implementation as well as the tests have been carried out in a laboratory with real industrial equipment, demonstrating the effectiveness of the presented solution.<\/jats:p>","DOI":"10.1007\/s11276-022-03212-5","type":"journal-article","created":{"date-parts":[[2023,1,6]],"date-time":"2023-01-06T16:09:04Z","timestamp":1673021344000},"page":"5077-5091","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":14,"title":["Low delay network attributes randomization to proactively mitigate reconnaissance attacks in industrial control systems"],"prefix":"10.1007","volume":"30","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-8241-7453","authenticated-orcid":false,"given":"Xabier","family":"Etxezarreta","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0387-9167","authenticated-orcid":false,"given":"I\u00f1aki","family":"Garitano","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9641-5646","authenticated-orcid":false,"given":"Mikel","family":"Iturbe","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3720-6048","authenticated-orcid":false,"given":"Urko","family":"Zurutuza","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2023,1,6]]},"reference":[{"key":"3212_CR1","doi-asserted-by":"publisher","unstructured":"Stouffer, K., Pillitteri, V., Lightman, S., Abrams, M., Hahn, A. (2015). Guide to industrial control systems (ics) security. https:\/\/doi.org\/10.6028\/NIST.SP.800-82r2","DOI":"10.6028\/NIST.SP.800-82r2"},{"key":"3212_CR2","doi-asserted-by":"crossref","unstructured":"Iturbe, M., Garitano, I., Zurutuza, U., Uribeetxeberria, R. (2016). Visualizing network flows and related anomalies in industrial networks using chord diagrams and whitelisting. In: VISIGRAPP (2: IVAPP), pp. 101\u2013108","DOI":"10.5220\/0005670000990106"},{"issue":"1","key":"3212_CR3","doi-asserted-by":"publisher","first-page":"709","DOI":"10.1109\/COMST.2019.2963791","volume":"22","author":"J-H Cho","year":"2020","unstructured":"Cho, J.-H., Sharma, D. P., Alavizadeh, H., Yoon, S., Ben-Asher, N., Moore, T. J., Kim, D. S., Lim, H., & Nelson, F. F. (2020). Toward proactive, adaptive defense: A survey on moving target defense. IEEE Communications Surveys Tutorials, 22(1), 709\u2013745. https:\/\/doi.org\/10.1109\/COMST.2019.2963791","journal-title":"IEEE Communications Surveys Tutorials"},{"issue":"1","key":"3212_CR4","doi-asserted-by":"publisher","first-page":"207","DOI":"10.1007\/s11390-019-1906-z","volume":"34","author":"J Zheng","year":"2019","unstructured":"Zheng, J., & Namin, A. S. (2019). A survey on the moving target defense strategies: An architectural perspective. Journal of Computer Science and Technology, 34(1), 207\u2013233.","journal-title":"Journal of Computer Science and Technology"},{"key":"3212_CR5","doi-asserted-by":"publisher","first-page":"577","DOI":"10.1007\/978-3-319-67180-2_56","volume-title":"International joint conference SOCO\u201917-CISIS\u201917-ICEUTE\u201917 Le\u00f3n, spain, september 6\u20138, 2017, proceeding","author":"M Sainz","year":"2018","unstructured":"Sainz, M., Iturbe, M., Garitano, I., & Zurutuza, U. (2018). Software defined networking opportunities for intelligent security enhancement of industrial control systems. In H. P\u00e9rez Garc\u00eda, J. Alfonso-Cend\u00f3n, L. S\u00e1nchez Gonz\u00e1lez, H. Quinti\u00e1n, & E. Corchado (Eds.), International joint conference SOCO\u201917-CISIS\u201917-ICEUTE\u201917 Le\u00f3n, spain, september 6\u20138, 2017, proceeding (pp. 577\u2013586). Cham: Springer."},{"key":"3212_CR6","doi-asserted-by":"publisher","unstructured":"Boucadair, M., & Jacquenet, C. (2014). Software-defined networking: A perspective from within a service provider environment. RFC Editor. https:\/\/doi.org\/10.17487\/RFC7149. https:\/\/www.rfc-editor.org\/info\/rfc7149","DOI":"10.17487\/RFC7149"},{"key":"3212_CR7","doi-asserted-by":"publisher","first-page":"407","DOI":"10.1016\/j.compeleceng.2017.05.013","volume":"66","author":"E Molina","year":"2018","unstructured":"Molina, E., & Jacob, E. (2018). Software-defined networking in cyber-physical systems: A survey. Computers and Electrical Engineering, 66, 407\u2013419. https:\/\/doi.org\/10.1016\/j.compeleceng.2017.05.013","journal-title":"Computers and Electrical Engineering"},{"key":"3212_CR8","doi-asserted-by":"publisher","unstructured":"Jafarian, J.H., Al-Shaer, E., & Duan, Q. (2012). Openflow random host mutation: Transparent moving target defense using software defined networking. In: Proceedings of the first workshop on hot topics in software defined networks. HotSDN \u201912, pp. 127\u2013132. Association for Computing Machinery, New York, NY, USA (2012). https:\/\/doi.org\/10.1145\/2342441.2342467","DOI":"10.1145\/2342441.2342467"},{"key":"3212_CR9","doi-asserted-by":"publisher","unstructured":"Sharma, D.P., Kim, D.S., Yoon, S., Lim, H., Cho, J.-H., & Moore, T.J. (2018) Frvm: Flexible random virtual ip multiplexing in software-defined networks. In: 2018 17th IEEE International Conference On Trust, Security And Privacy In Computing And Communications\/ 12th IEEE International Conference On Big Data Science And Engineering (TrustCom\/BigDataSE), pp. 579\u2013587. https:\/\/doi.org\/10.1109\/TrustCom\/BigDataSE.2018.00088","DOI":"10.1109\/TrustCom\/BigDataSE.2018.00088"},{"key":"3212_CR10","doi-asserted-by":"publisher","unstructured":"Chowdhary, A., Alshamrani, A., Huang, D., & Liang, H. (2018). Mtd analysis and evaluation framework in software defined network (mason). In: Proceedings of the 2018 ACM international workshop on security in software defined networks & network function virtualization. SDN-NFV Sec\u201918, pp. 43\u201348. Association for Computing Machinery, New York, NY, USA. https:\/\/doi.org\/10.1145\/3180465.3180473","DOI":"10.1145\/3180465.3180473"},{"issue":"1","key":"3212_CR11","doi-asserted-by":"publisher","first-page":"751","DOI":"10.1109\/TNSE.2021.3052090","volume":"8","author":"A Aydeger","year":"2021","unstructured":"Aydeger, A., Manshaei, M. H., Rahman, M. A., & Akkaya, K. (2021). Strategic defense against stealthy link flooding attacks: A signaling game approach. IEEE Transactions on Network Science and Engineering, 8(1), 751\u2013764. https:\/\/doi.org\/10.1109\/TNSE.2021.3052090","journal-title":"IEEE Transactions on Network Science and Engineering"},{"key":"3212_CR12","doi-asserted-by":"crossref","unstructured":"Skowyra, R., Bauer, K., Dedhia, V., & Okhravi, H. (2016). Have no phear: Networks without identifiers. In: Proceedings of the 2016 ACM workshop on moving target defense, pp. 3\u201314","DOI":"10.1145\/2995272.2995276"},{"key":"3212_CR13","doi-asserted-by":"publisher","unstructured":"Wang, Y., Chen, Q., Yi, J., & Guo, J. (2017). U-tri: Unlinkability through random identifier for sdn network. In: Proceedings of the 2017 workshop on moving target defense. MTD \u201917, pp. 3\u201315. Association for Computing Machinery, New York, NY, USA. https:\/\/doi.org\/10.1145\/3140549.3140554","DOI":"10.1145\/3140549.3140554"},{"key":"3212_CR14","doi-asserted-by":"crossref","unstructured":"Chavez, A.R., Stout, W.M., & Peisert, S. (2015) Techniques for the dynamic randomization of network attributes. In: 2015 international carnahan conference on security technology (ICCST), pp. 1\u20136. IEEE","DOI":"10.1109\/CCST.2015.7389661"},{"key":"3212_CR15","doi-asserted-by":"publisher","first-page":"5366","DOI":"10.1109\/TIFS.2021.3127009","volume":"16","author":"Y Zhou","year":"2021","unstructured":"Zhou, Y., Cheng, G., & Yu, S. (2021). An sdn-enabled proactive defense framework for ddos mitigation in iot networks. IEEE Transactions on Information Forensics and Security, 16, 5366\u20135380. https:\/\/doi.org\/10.1109\/TIFS.2021.3127009","journal-title":"IEEE Transactions on Information Forensics and Security"},{"key":"3212_CR16","doi-asserted-by":"crossref","unstructured":"Kampanakis, P., Perros, H., & Beyene, T. (2014). Sdn-based solutions for moving target defense network protection. In: Proceeding of IEEE international symposium on a world of wireless, mobile and multimedia networks 2014, pp. 1\u20136. IEEE","DOI":"10.1109\/WoWMoM.2014.6918979"},{"key":"3212_CR17","doi-asserted-by":"publisher","unstructured":"Koo, H., Chen, Y., Lu, L., Kemerlis, V.P., & Polychronakis, M. (2018). Compiler-assisted code randomization. In: 2018 IEEE symposium on security and privacy (SP), pp. 461\u2013477. https:\/\/doi.org\/10.1109\/SP.2018.00029","DOI":"10.1109\/SP.2018.00029"},{"key":"3212_CR18","doi-asserted-by":"publisher","unstructured":"Huang, Y., & Ghosh, A.K. (2011). Introducing diversity and uncertainty to create moving attack surfaces for web services. Springer New York, 131\u2013151. https:\/\/doi.org\/10.1007\/978-1-4614-0977-9_8","DOI":"10.1007\/978-1-4614-0977-9_8"},{"key":"3212_CR19","doi-asserted-by":"publisher","unstructured":"Taguinod, M., Doup\u00e9, A., Zhao, Z., & Ahn, G.-J. (2015). Toward a moving target defense for web applications. In: 2015 IEEE international conference on information reuse and integration, pp. 510\u2013517. https:\/\/doi.org\/10.1109\/IRI.2015.84","DOI":"10.1109\/IRI.2015.84"},{"key":"3212_CR20","doi-asserted-by":"publisher","unstructured":"Li, Y., Dai, R., Zhang, J. (2014). Morphing communications of cyber-physical systems towards moving-target defense. In: 2014 IEEE international conference on communications (ICC), pp. 592\u2013598. https:\/\/doi.org\/10.1109\/ICC.2014.6883383","DOI":"10.1109\/ICC.2014.6883383"},{"issue":"3","key":"3212_CR21","doi-asserted-by":"publisher","first-page":"1029","DOI":"10.1109\/TAC.2019.2915746","volume":"65","author":"A Kanellopoulos","year":"2020","unstructured":"Kanellopoulos, A., & Vamvoudakis, K. G. (2020). A moving target defense control framework for cyber-physical systems. IEEE Transactions on Automatic Control, 65(3), 1029\u20131043. https:\/\/doi.org\/10.1109\/TAC.2019.2915746","journal-title":"IEEE Transactions on Automatic Control"},{"key":"3212_CR22","doi-asserted-by":"publisher","unstructured":"Alavizadeh, H., Hong, J.B., Jang-Jaccard, J., & Kim, D.S. (2018). Comprehensive security assessment of combined mtd techniques for the cloud. In: Proceedings of the 5th ACM workshop on moving target defense. MTD \u201918, pp. 11\u201320. Association for Computing Machinery, New York, NY, USA . https:\/\/doi.org\/10.1145\/3268966.3268967","DOI":"10.1145\/3268966.3268967"},{"key":"3212_CR23","doi-asserted-by":"publisher","unstructured":"Alavizadeh, H., Jang-Jaccard, J., & Kim, D.S. (2018). Evaluation for combination of shuffle and diversity on moving target defense strategy for cloud computing. In: 2018 17th IEEE international conference on trust, security and privacy in computing and communications\/ 12th IEEE international conference on big data science and engineering (TrustCom\/BigDataSE), pp. 573\u2013578 .https:\/\/doi.org\/10.1109\/TrustCom\/BigDataSE.2018.00087","DOI":"10.1109\/TrustCom\/BigDataSE.2018.00087"},{"key":"3212_CR24","unstructured":"netfilter.org project, T.: Netfilter: Firewalling, NAT and Packet Mangling for Linux. https:\/\/www.netfilter.org\/ Accessed 2022-07-27"},{"key":"3212_CR25","doi-asserted-by":"publisher","unstructured":"Ulrich, J., Drahos, J., & Govindarasu, M. (2017). A symmetric address translation approach for a network layer moving target defense to secure power grid networks. In: 2017 Resilience week (RWS), pp. 163\u2013169 (2017). https:\/\/doi.org\/10.1109\/RWEEK.2017.8088667","DOI":"10.1109\/RWEEK.2017.8088667"},{"key":"3212_CR26","doi-asserted-by":"publisher","unstructured":"Pappa, A.C., Ashok, A & Govindarasu, M. (2017). Moving target defense for securing smart grid communications: Architecture, implementation amp; evaluation. In: 2017 IEEE power energy society innovative smart grid technologies conference (ISGT), pp. 1\u20135. https:\/\/doi.org\/10.1109\/ISGT.2017.8085954","DOI":"10.1109\/ISGT.2017.8085954"},{"key":"3212_CR27","doi-asserted-by":"publisher","unstructured":"Germano\u00a0da Silva, E., Dias\u00a0Knob, L.A., Wickboldt, J.A., Gaspary, L.P., Granville, L.Z., & Schaeffer-Filho, A. (2015). Capitalizing on sdn-based scada systems: An anti-eavesdropping case-study. In: 2015 IFIP\/IEEE international symposium on integrated network management (IM), pp. 165\u2013173 (2015). https:\/\/doi.org\/10.1109\/INM.2015.7140289","DOI":"10.1109\/INM.2015.7140289"},{"key":"3212_CR28","doi-asserted-by":"publisher","unstructured":"Ndonda, G.K., & Sadre, R. (2017). A low-delay sdn-based countermeasure to eavesdropping attacks in industrial control systems. In: 2017 IEEE conference on network function virtualization and software defined networks (NFV-SDN), pp. 1\u20137. https:\/\/doi.org\/10.1109\/NFV-SDN.2017.8169840","DOI":"10.1109\/NFV-SDN.2017.8169840"},{"key":"3212_CR29","doi-asserted-by":"crossref","unstructured":"Chavez, A.R. (2019). Moving target defense to improve industrial control system resiliency. In: industrial control systems security and resiliency, pp. 143\u2013167. Springer","DOI":"10.1007\/978-3-030-18214-4_8"},{"key":"3212_CR30","doi-asserted-by":"publisher","unstructured":"3rd, D.E.E., & Abley, J. (2013). IANA considerations and IETF protocol and documentation usage for IEEE 802 parameters. RFC editor. https:\/\/doi.org\/10.17487\/RFC7042. https:\/\/www.rfc-editor.org\/info\/rfc7042","DOI":"10.17487\/RFC7042"},{"key":"3212_CR31","unstructured":"Foundation, O.N. OpenFlow switch specification, Version 1.3.5. https:\/\/opennetworking.org\/wp-content\/uploads\/2014\/10\/openflow-switch-v1.3.5.pdf Accessed 2022-07-12"},{"key":"3212_CR32","unstructured":"Ryu SDN Framework. https:\/\/ryu-sdn.org\/ Accessed 2022-07-27"},{"key":"3212_CR33","doi-asserted-by":"publisher","first-page":"177460","DOI":"10.1109\/ACCESS.2019.2958284","volume":"7","author":"\u00c1LP G\u00f3mez","year":"2019","unstructured":"G\u00f3mez, \u00c1. L. P., Maim\u00f3, L. F., Celdran, A. H., Clemente, F. J. G., Sarmiento, C. C., Masa, C. J. D. C., & Nistal, R. M. (2019). On the generation of anomaly detection datasets in industrial control systems. IEEE Access, 7, 177460\u2013177473. https:\/\/doi.org\/10.1109\/ACCESS.2019.2958284","journal-title":"IEEE Access"},{"issue":"4","key":"3212_CR34","doi-asserted-by":"publisher","first-page":"2248","DOI":"10.1109\/COMST.2021.3094360","volume":"23","author":"M Conti","year":"2021","unstructured":"Conti, M., Donadel, D., & Turrin, F. (2021). A survey on industrial control system testbeds and datasets for security research. IEEE Communications Surveys & Tutorials, 23(4), 2248\u20132294.","journal-title":"IEEE Communications Surveys & Tutorials"},{"key":"3212_CR35","unstructured":"Barbieri, G., Conti, M., Tippenhauer, N.O., & Turrin, F. (2020). Sorry, shodan is not enough! assessing ICS security via IXP network traffic analysis. CoRR abs\/2007.01114 2007.01114"},{"key":"3212_CR36","unstructured":"Assante, M.J., & Lee, R.M. (2015). The industrial control system cyber kill chain. SANS Institute InfoSec Reading Room 1"},{"key":"3212_CR37","unstructured":"Nmap: the Network Mapper - Free Security Scanner. https:\/\/nmap.org\/ Accessed 2022-07-17"},{"key":"3212_CR38","doi-asserted-by":"crossref","unstructured":"Zhao, Z., Liu, F., & Gong, D. (2017). An sdn-based fingerprint hopping method to prevent fingerprinting attacks. Security and Communication Networks 2017","DOI":"10.1155\/2017\/1560594"},{"key":"3212_CR39","doi-asserted-by":"publisher","DOI":"10.6028\/NIST.SP.800-160v2","volume-title":"Developing cyber resilient systems: A systems security engineering approach","author":"R Ross","year":"2019","unstructured":"Ross, R., Pillitteri, V., Graubart, R., Bodeau, D., & McQuaid, R. (2019). Developing cyber resilient systems: A systems security engineering approach. National Institute of Standards and Technology: Technical report."}],"container-title":["Wireless Networks"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11276-022-03212-5.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s11276-022-03212-5\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11276-022-03212-5.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,8,2]],"date-time":"2024-08-02T16:23:50Z","timestamp":1722615830000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s11276-022-03212-5"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,1,6]]},"references-count":39,"journal-issue":{"issue":"6","published-print":{"date-parts":[[2024,8]]}},"alternative-id":["3212"],"URL":"https:\/\/doi.org\/10.1007\/s11276-022-03212-5","relation":{},"ISSN":["1022-0038","1572-8196"],"issn-type":[{"value":"1022-0038","type":"print"},{"value":"1572-8196","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,1,6]]},"assertion":[{"value":"13 December 2022","order":1,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"6 January 2023","order":2,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare that they have no known competing financial interests or personal relationships that could have appeared to influence the work reported in this paper.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}}]}}