首页> 外文会议>IEEE Conference on Communications and Network Security >CONCEAL: A Strategy Composition for Resilient Cyber Deception-Framework, Metrics and Deployment
【24h】

CONCEAL: A Strategy Composition for Resilient Cyber Deception-Framework, Metrics and Deployment

机译:CONCEAL:弹性网络欺骗的战略组成-框架,指标和部署

获取原文

摘要

Cyber deception is a key proactive cyber resilience technique to reverse the current asymmetry that favors adversaries in cyber warfare by creating a significant confusion in discovering and targeting cyber assets. One of the key objectives for cyber deception is to hide the true identity of the cyber assets in order to effectively deflect adversaries away from critical targets, and detect their activities early in the killchain.Although many cyber deception techniques were proposed including using honeypots to represent fake targets, and mutating IP addresses to frequently change the ground truth of the network configuration [12], none of these deception techniques is resilient enough to provide high confidence of concealing the identity of the network assets, particularly against sophisticated attackers. In fact, in this paper our analytical and experimental work showed that highly resilient cyber deception is unlikely attainable using a single technique, but it requires an optimal composition of various concealment techniques to maximize the deception utility. We, therefore, present a new cyber deception framework, called CONCEAL, which is a composition of mutation, anonymity, and diversity to maximize key deception objectives, namely, concealability, detectability and deterrence, while constraining the overall deployment cost. We formally define the CONCEAL metrics for concealability, detectability, and deterrence to measure the effectiveness of CONCEAL. Finally, we present the deployment of CONCEAL as a service to achieve manageability and cost-effectiveness by automatically generating the optimal deception proxy configuration based on existing hostetwork configuration, risk constraints of network services, and budget constraints. Our evaluation experiments measure both the deception effectiveness based on the above metrics, as well as the scalability of the CONCEAL framework.
机译:网络欺骗是一项关键的主动网络弹性技术,可通过在发现和瞄准网络资产方面造成重大混乱来逆转当前对网络战争中的对手有利的不对称性。网络欺骗的主要目标之一是隐藏网络资产的真实身份,以便有效地使对手远离关键目标,并在杀伤链中尽早发现他们的活动。尽管提出了许多网络欺骗技术,包括使用蜜罐来表示。伪造的目标,以及更改IP地址以经常更改网络配置的基本事实[12],这些欺骗技术都没有足够的弹性来提供隐藏网络资产身份的高置信度,尤其是针对复杂的攻击者。实际上,在本文中,我们的分析和实验工作表明,使用单一技术不可能实现高度弹性的网络欺骗,但它需要各种隐藏技术的最佳组合才能最大化欺骗的效用。因此,我们提出了一种称为CON​​CEAL的新的网络欺骗框架,该框架由突变,匿名和多样性组成,以最大限度地提高关键的欺骗目标(即隐蔽性,可检测性和威慑力),同时限制了总体部署成本。我们正式定义隐匿性,可检测性和威慑力的CONCEAL度量标准,以衡量CONCEAL的有效性。最后,我们介绍CONCEAL作为一项服务的部署,以通过基于现有主机/网络配置,网络服务的风险约束和预算约束自动生成最佳欺骗代理配置来实现可管理性和成本效益。我们的评估实验基于上述指标来衡量欺骗效果以及CONCEAL框架的可伸缩性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号