Like any smart soldier, good cyberwarriors conduct proper reconnaissance of a network before they hack into it. To that end, the Air Force has put out a research proposal for counter-reconnaissance systems for its networks.
Resource: Read the Proposal
There are actually two types of network reconnaissance, according to the Air Force: Passive, which is merely collecting open-source information, or active, which is breaking into network hosts and servers.
The Air Force’s goal is to make network reconnaissance harder and therefore the subsequent attacks less effective. “Such solutions must effectively prevent traffic analysis, and must implement evasive and deceptive techniques such as misreporting source and destination IP and/or MAC addresses, and intermittently changing those addresses,” the Air Force said. “The technology must be capable of preventing an adversary from accurately determining the direction or volume of information moving within the network, or the size or topology of the network itself, and must be capable of taking measures to prevent, detect, and cease communication with non-compliant or rogue clients within the environment.”
Solutions should have minimal impact on network performance, should not require custom components, and should support PKI or other robust cryptosystems.




