首页> 外文会议>IEEE International Conference on Systems, Man, and Cybernetics >Intrusion detection system using Honey Token based Encrypted Pointers to mitigate cyber threats for critical infrastructure networks
【24h】

Intrusion detection system using Honey Token based Encrypted Pointers to mitigate cyber threats for critical infrastructure networks

机译:入侵检测系统使用基于Honey Token的加密指针减轻关键基础设施网络的网络威胁

获取原文

摘要

Recent advancements in cyberspace impose a greater threat to the security of critical infrastructure than ever before. The scale of damage that could be done on these infrastructures by well-planned cyber-attacks is enormous. Most of the research work done for the security of these critical infrastructures focuses on conventional security measures. In this paper, we designed an Intrusion Detection System (IDS) that is based on the novel approach of Honey Token based Encrypted Pointers to prevent critical infrastructure networks from cyber-attacks particularly from zero day cyber threats. These honey tokens inside the frame will serve as a trap for the attacker. All nodes operating within the working domain of critical infrastructure network are divided into four different pools. This division is based according to their computational power and level of vulnerability. These pools are provided with different levels of security measures within the network. IDS use different number of Honey Tokens (HT) per frame for every different pool. Moreover every pool uses different types of encryption schemes (AES-128,192,256) etc. We use critical infrastructure network of 64 nodes for our simulations. We analyzed the performance of IDS in terms of True Positive and False Negative Alarms. Finally we test this IDS through Network Penetration Testing (NPT). This NPT is accomplished by putting the critical infrastructure network of 64 nodes directly under the zero day cyber-attacks and then we analyze the behavior of the IDS under such realistic conditions. The IDS is designed in such a way that it not only detects the intrusions but also recovers the entire zero day attack using reverse engineering approach.
机译:网络空间的最新发展比以往任何时候都对关键基础设施的安全性构成了更大的威胁。精心设计的网络攻击可能会对这些基础架构造成巨大的破坏。为这些关键基础设施的安全性所做的大多数研究工作都集中在常规安全措施上。在本文中,我们设计了一种基于基于Honey Token的加密指针的新颖方法的入侵检测系统(IDS),以防止关键基础设施网络受到网络攻击,特别是零日网络威胁。框架内的这些蜂蜜令牌将成为攻击者的陷阱。在关键基础架构网络的工作域内运行的所有节点都分为四个不同的池。该划分基于其计算能力和易受攻击性级别。这些池在网络中具有不同级别的安全措施。对于每个不同的池,IDS每帧使用不同数量的蜂蜜令牌(HT)。此外,每个池使用不同类型的加密方案(AES-128,192,256)等。我们使用64个节点的关键基础架构网络进行仿真。我们根据真实肯定和错误否定警报来分析IDS的性能。最后,我们通过网络渗透测试(NPT)测试此IDS。这项NPT是通过将64个节点的关键基础架构网络直接置于零日网络攻击之下来实现的,然后我们分析了在这种现实条件下IDS的行为。 IDS的设计方式使其不仅可以检测到入侵,还可以使用逆向工程方法恢复整个零日攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号