Download PDFOpen PDF in browserAttacker Profiling through MTD-Elicited Behavioral Evidence and Mutation-Aware IDS Observation16 pages•Published: August 6, 2026AbstractConventional Intrusion Detection Systems (IDSs) are often deployed in static environments, where the defender's view of attackers is largely limited to direct evidence of observed attack attempts, such as request patterns, payload characteristics, and the alerts they trigger. Although such information is useful for detection, it provides only a limited view of how an attack is carried out by an attacker against a target system. Moving Target Defense (MTD) can expand this view by repeatedly invalidating attacker knowledge and forcing adversaries to disclose additional behavioral reactions, such as renewed scanning, access to expired targets and decoy interaction. However, existing studies have mostly discussed such reactions at the level of detection or visibility enhancement, while their potential for further attacker profiling remains insufficiently explored.This paper proposes an MTD-aware attacker profiling framework that transforms MTD-elicited reactions into structured behavioral evidence. By incorporating MTD service-state knowledge into IDS observation, the framework enables attacker interactions to be interpreted according to their mutation context rather than as isolated traffic events. We evaluate the framework in a controlled Docker-based web testbed using multiple simulated attackers with different behavioral tendencies. The results show that, compared with static IDS observation without MTD, mutation-aware IDS under MTD-driven mutation provides additional behavioral dimensions that make attacker differences more interpretable and distinguishable, enabling profiling-oriented analysis beyond visibility enhancement. Keyphrases: attacker profiling, behavioral evidence, cyber deception, intrusion detection system, moving target defense, mutation aware observation In: Tung-Tso Tsai, Huy Kang Kim, Yujue Wang and Akira Yamada (editors). Proceedings of The 21st Asia Joint Conference on Information Security, vol 111, pages 17-32.
|

