
Modern security design assumes that preventing attacks is the primary goal, delegating the handling of post-intrusion contaminated states to after-the-fact forensic investigation. However, when an attacker breaches the first line of defense, the contaminated execution state persists in the system, providing a foothold for lateral movement, long-term persistence, and evidence destruction. We propose Volatile Cyber Defense (VCD) as a new defense paradigm to address this problem. VCD is based on the design principle: "when an attack is detected, the process immediately preserves evidence and self-destructs, then recovers in a clean state." Unlike existing approaches such as Moving Target Defense, Phoenix Servers, and Intrusion Tolerance, VCD is unique in simultaneously adopting detection-triggered immediate self-destruction, forensics-first termination, and autonomous recovery as its core design principles — a combination with no precedent in prior research. This paper demonstrates the technical feasibility of VCD through a multi-layer volatile implementation using Elixir/OTP and Kubernetes at both the process and container levels.
| selected citations These citations are derived from selected sources. This is an alternative to the "Influence" indicator, which also reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically). | 0 | |
| popularity This indicator reflects the "current" impact/attention (the "hype") of an article in the research community at large, based on the underlying citation network. | Average | |
| influence This indicator reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically). | Average | |
| impulse This indicator reflects the initial momentum of an article directly after its publication, based on the underlying citation network. | Average |
