{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,15]],"date-time":"2025-10-15T00:44:54Z","timestamp":1760489094366,"version":"build-2065373602"},"reference-count":31,"publisher":"MDPI AG","issue":"23","license":[{"start":{"date-parts":[[2022,12,6]],"date-time":"2022-12-06T00:00:00Z","timestamp":1670284800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"Commonwealth Cyber Initiative"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>Federated clouds are interconnected cooperative cloud infrastructures offering vast hosting capabilities, smooth workload migration and enhanced reliability. However, recent devastating attacks on such clouds have shown that such features come with serious security challenges. The oblivious heterogeneous construction, management, and policies employed in federated clouds open the door for attackers to induce conflicts to facilitate pervasive coordinated attacks. In this paper, we present a novel proactive defense that aims to increase attacker uncertainty and complicate target tracking, a critical step for successful coordinated attacks. The presented systemic approach acts as a VM management platform with an intrinsic multidimensional hierarchical attack representation model (HARM) guiding a dynamic, self and situation-aware VM live-migration for moving-target defense (MtD). The proposed system managed to achieve the proposed goals in a resource-, energy-, and cost-efficient manner.<\/jats:p>","DOI":"10.3390\/s22239548","type":"journal-article","created":{"date-parts":[[2022,12,7]],"date-time":"2022-12-07T05:50:52Z","timestamp":1670392252000},"page":"9548","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["Moving-Target Defense in Depth: Pervasive Self- and Situation-Aware VM Mobilization across Federated Clouds in Presence of Active Attacks"],"prefix":"10.3390","volume":"22","author":[{"given":"Yousra","family":"Magdy","sequence":"first","affiliation":[{"name":"Electrical Engineering Department, Faculty of Engineering, Alexandria University, Alexandria 21519, Egypt"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9386-4726","authenticated-orcid":false,"given":"Mohamed","family":"Azab","sequence":"additional","affiliation":[{"name":"Department of Computer and Information Sciences, Virginia Military Institute, Lexington, VA 24450, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Amal","family":"Hamada","sequence":"additional","affiliation":[{"name":"Electrical Engineering Department, Faculty of Engineering, Alexandria University, Alexandria 21519, Egypt"},{"name":"Management Information System (MIS) Department, High Institute of Computer and Information Systems (HICIS), Aboukir High Institutions, Alexandria 21625, Egypt"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mohamed R. M.","family":"Rizk","sequence":"additional","affiliation":[{"name":"Electrical Engineering Department, Faculty of Engineering, Alexandria University, Alexandria 21519, Egypt"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Nayera","family":"Sadek","sequence":"additional","affiliation":[{"name":"Electrical Engineering Department, Faculty of Engineering, Alexandria University, Alexandria 21519, Egypt"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2022,12,6]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"102580","DOI":"10.1016\/j.cose.2021.102580","article-title":"Cloud computing security: A survey of service-based models","volume":"114","author":"Parast","year":"2022","journal-title":"Comput. Secur."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1007\/s10922-021-09594-9","article-title":"A cost-aware management framework for placement of data-intensive applications on federated cloud","volume":"29","author":"Najm","year":"2021","journal-title":"J. Netw. Syst. Manag."},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"e4271","DOI":"10.1002\/ett.4271","article-title":"Defending co-resident attack using reputation-based virtual machine deployment policy in cloud computing","volume":"32","author":"Xiao","year":"2021","journal-title":"Trans. Emerg. Telecommun. Technol."},{"key":"ref_4","first-page":"012067","article-title":"Co-Resident Attack and its impact on Virtual Environment","volume":"Volume 2327","author":"Jena","year":"2022","journal-title":"Proceedings of the Journal of Physics: Conference Series"},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"9493","DOI":"10.1007\/s11227-020-03213-1","article-title":"A survey on security challenges in cloud computing: Issues, threats, and solutions","volume":"76","author":"Tabrizchi","year":"2020","journal-title":"J. Supercomput."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"1909","DOI":"10.1109\/COMST.2020.2982955","article-title":"A survey of moving target defenses for network security","volume":"22","author":"Sengupta","year":"2020","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"709","DOI":"10.1109\/COMST.2019.2963791","article-title":"Toward proactive, adaptive defense: A survey on moving target defense","volume":"22","author":"Cho","year":"2020","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"207","DOI":"10.1007\/s11390-019-1906-z","article-title":"A survey on the moving target defense strategies: An architectural perspective","volume":"34","author":"Zheng","year":"2019","journal-title":"J. Comput. Sci. Technol."},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"3759626","DOI":"10.1155\/2018\/3759626","article-title":"Moving target defense techniques: A survey","volume":"2018","author":"Lei","year":"2018","journal-title":"Secur. Commun. Netw."},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"102091","DOI":"10.1016\/j.cose.2020.102091","article-title":"Evaluating the effectiveness of shuffle and redundancy mtd techniques in the cloud","volume":"102","author":"Alavizadeh","year":"2021","journal-title":"Comput. Secur."},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"163","DOI":"10.1109\/TDSC.2015.2443790","article-title":"Assessing the effectiveness of moving target defenses using security models","volume":"13","author":"Hong","year":"2015","journal-title":"IEEE Trans. Dependable Secur. Comput."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"100304","DOI":"10.1016\/j.cosrev.2020.100304","article-title":"A survey of live virtual machine migration techniques","volume":"38","author":"Le","year":"2020","journal-title":"Comput. Sci. Rev."},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Smimite, O., and Afdel, K. (2020). Containers placement and migration on cloud system. arXiv.","DOI":"10.5120\/ijca2020920493"},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Azab, M., and Eltoweissy, M. (2016, January 22\u201326). Migrate: Towards a lightweight moving-target defense against cloud side-channels. Proceedings of the 2016 IEEE Security and Privacy Workshops (SPW), San Jose, CA, USA.","DOI":"10.1109\/SPW.2016.28"},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Ali, D., and Gupta, M.K. (2021). Advanced Deadline-Sensitive Scheduling Approaches in Cloud Computing. Advances in Computational Intelligence and Communication Technology, Springer.","DOI":"10.1007\/978-981-15-1275-9_26"},{"key":"ref_16","unstructured":"Shams, A., Sharif, H., and Helfert, M. (2022, November 13). A Novel Model for Cloud Computing Analytics and Measurement. Available online: https:\/\/www.researchgate.net\/publication\/350691152_A_Novel_Model_for_Cloud_Computing_Analytics_and_Measurement."},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Chouhan, L., Bansal, P., Lauhny, B., and Chaudhary, Y. (2020). A survey on cloud federation architecture and challenges. Social Networking and Computational Intelligence, Springer.","DOI":"10.1007\/978-981-15-2071-6_5"},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1007\/s41109-020-00256-4","article-title":"Security through block vault in a blockchain enabled federated cloud framework","volume":"5","author":"Malomo","year":"2020","journal-title":"Appl. Netw. Sci."},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Amara, N., Zhiqui, H., and Ali, A. (2017, January 12\u201314). Cloud computing security threats and attacks with their mitigation techniques. Proceedings of the 2017 International Conference on Cyber-Enabled Distributed Computing and Knowledge Discovery (CyberC), Nanjing, China.","DOI":"10.1109\/CyberC.2017.37"},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"1122","DOI":"10.1631\/FITEE.1601321","article-title":"Moving target defense: State of the art and characteristics","volume":"17","author":"Cai","year":"2016","journal-title":"Front. Inf. Technol. Electron. Eng."},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Magdy, Y., Kashkoush, M.S., Azab, M., and Rizk, M.R. (2020, January 11\u201314). Anonymous blockchain Based Routing For Moving-target Defense Across Federated Clouds. Proceedings of the 2020 IEEE 21st International Conference on High Performance Switching and Routing (HPSR), Newark, NJ, USA.","DOI":"10.1109\/HPSR48589.2020.9098983"},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"1772","DOI":"10.1109\/TETC.2022.3155272","article-title":"Evaluating the Security and Economic Effects of Moving Target Defense Techniques on the Cloud","volume":"10","author":"Alavizadeh","year":"2022","journal-title":"IEEE Trans. Emerg. Top. Comput."},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"507","DOI":"10.1016\/j.future.2019.10.009","article-title":"Model-based evaluation of combinations of shuffle and diversity MTD techniques on the cloud","volume":"111","author":"Alavizadeh","year":"2020","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Alavizadeh, H., Jang-Jaccard, J., and Kim, D.S. (2018, January 1\u20133). Evaluation for combination of shuffle and diversity on moving target defense strategy for cloud computing. Proceedings of the 2018 17th IEEE International Conference on Trust, Security and Privacy in Computing and Communications\/12th IEEE International Conference on Big Data Science and Engineering (TrustCom\/BigDataSE), New York, NY, USA.","DOI":"10.1109\/TrustCom\/BigDataSE.2018.00087"},{"key":"ref_25","unstructured":"(2022, November 13). CVE. Available online: https:\/\/cve.mitre.org\/."},{"key":"ref_26","unstructured":"(2022, November 13). NVD, Available online: https:\/\/nvd.nist.gov\/vuln-metrics\/cvss."},{"key":"ref_27","unstructured":"Hong, J., and Kim, D.S. (2022, November 13). Harms: Hierarchical Attack Representation Models for Network Security Analysis. Available online: https:\/\/ro.ecu.edu.au\/ism\/146\/."},{"key":"ref_28","unstructured":"Haque, S., Keffeler, M., and Atkison, T. (2017, January 25\u201327). An evolutionary approach of attack graphs and attack trees: A survey of attack modeling. Proceedings of the International Conference on Security and Management (SAM), San Francisco, CA, USA."},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Alavizadeh, H., Kim, D.S., Hong, J.B., and Jang-Jaccard, J. (2017). Effective security analysis for combinations of mtd techniques on cloud computing (short paper). Proceedings of the International Conference on Information Security Practice and Experience, Springer.","DOI":"10.1007\/978-3-319-72359-4_32"},{"key":"ref_30","unstructured":"Alavizadeh, H. (2019). Effective Security Analysis for Combinations of Mtd Techniques on Cloud Computing: A Thesis Submitted in Partial Fulfilment of the Requirements for the Degree of Doctor of Philosophy (ph. d.) in Computer Science, Massey University. [Ph.D. Thesis, Massey University]."},{"key":"ref_31","unstructured":"(2022, October 27). NVD-CVE-2021-0425, Available online: https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2021-0425."}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/22\/23\/9548\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T01:35:03Z","timestamp":1760146503000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/22\/23\/9548"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,12,6]]},"references-count":31,"journal-issue":{"issue":"23","published-online":{"date-parts":[[2022,12]]}},"alternative-id":["s22239548"],"URL":"https:\/\/doi.org\/10.3390\/s22239548","relation":{},"ISSN":["1424-8220"],"issn-type":[{"type":"electronic","value":"1424-8220"}],"subject":[],"published":{"date-parts":[[2022,12,6]]}}}