【24h】

Cross-Stack Threat Sensing for Cyber Security and Resilience

机译:跨堆栈威胁感知,可确保网络安全和弹性

获取原文
获取外文期刊封面目录资料

摘要

We propose a novel cross-stack sensor framework for realizing lightweight, context-aware, high-interaction network and endpoint deceptions for attacker disinformation, misdirection, monitoring, and analysis. In contrast to perimeter-based honeypots, the proposed method arms production workloads with deceptive attack-response capabilities via injection of booby-traps at the network, endpoint, operating system, and application layers. This provides defenders with new, potent tools for more effectively harvesting rich cyber-threat data from the myriad of attacks launched by adversaries whose identities and methodologies can be better discerned through direct engagement rather than purely passive observations of probe attempts. Our research provides new tactical deception capabilities for cyber operations, including new visibility into both enterprise and national interest networks, while equipping applications and endpoints with attack awareness and active mitigation capabilities.
机译:我们提出了一种新颖的跨栈传感器框架,用于实现轻量级,上下文感知,高交互性的网络以及针对攻击者的虚假信息,误导,监视和分析的端点欺骗。与基于外围的蜜罐相反,该方法通过在网络,端点,操作系统和应用程序层注入诱杀陷阱,使生产工作负载具有欺骗性的攻击响应能力。这为防御者提供了新的有效工具,可以更有效地从敌人发起的无数次攻击中收集丰富的网络威胁数据,这些攻击者的身份和方法可以通过直接参与而不是纯粹的被动观察来更好地识别。我们的研究为网络运营提供了新的战术欺骗功能,包括对企业和国家利益网络的新可见性,同时为应用程序和端点配备了攻击意识和主动缓解功能。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号