Moving target defense case study · Case Studies

Mission-Invariant Architecture Morphing (MIAM)

A formal architecture for changing an application's internal service graph so post-access reconnaissance can lose value across security epochs.

Problem

After initial access, an attacker can map dependencies, trust relationships, credentials, and lateral paths. Many moving-target defenses change addresses, ports, hosts, or variants without necessarily invalidating the application's deeper dependency map.

Why common approaches fall short

  • Changing location or surface identifiers does not guarantee that learned internal relationships become unusable.
  • A small repeating variant pool lets an attacker relearn or eventually retain knowledge of every recurring state.
  • Reconfiguration can create its own risk if mission state, secrets, or compromised runtime state cross the transition boundary without explicit rules.

THOR-SEC approach

MIAM moves the transformation boundary into the application by reassigning capability units across certified runtime service graphs while keeping the external mission interface stable.

A graph delta and capability-state map drive a State Continuity Firewall, while fresh epoch authority is intended to isolate credentials and runtime state between transitions.

Evidence

  • The v1.0.0 paper defines an operational reconnaissance-transfer model, architecture-distance measures, cryptographic epoch isolation, a State Continuity Firewall, and an ablation-based evaluation protocol.
  • The recurrence model shows mathematically that a finite certified variant pool leaves a nonzero retained-knowledge floor; faster rotation alone cannot remove that floor.
  • A reproduction script checks the paper's arithmetic, and the paper and source are archived with DOI 10.5281/zenodo.23001045.

Limitations

  • The work is a design proposal and formal model. It reports no empirical security advantage.
  • Common-mode vulnerabilities survive if every graph shares the same vulnerable library, secret, API logic, or trust decision.
  • The measured benefit of graph morphing must be separated experimentally from rejuvenation and credential rotation.
  • A compromised control plane or poisoned telemetry could undermine the design and may become an attack primitive.

Current status

Formal design; empirical validation pending

Formal design proposal and defensive publication. The paper defines how to test the idea; empirical efficacy and operational overhead remain unmeasured.