首页> 外文会议>IFIP/IEEE Symposium on Integrated Network and Service Management >Mitigation of Multi-vector Network Attacks via Orchestration of Distributed Rule Placement
【24h】

Mitigation of Multi-vector Network Attacks via Orchestration of Distributed Rule Placement

机译:通过编排分布式规则放置来缓解多向量网络攻击

获取原文

摘要

In this paper we propose a framework for mitigating detected multi-vector anomalies in typical enterprise networks via the distribution of Access Control Rules. Our distributed, non-proprietary approach takes advantage of the capabilities offered by all devices along an attack path enhancing their mitigation potential. These devices are organized into distinct defense stages and network operators express their defense preferences for specific attack types. Our mechanism automatically assigns generic mitigation rules to each stage. Subsequently, device-specific access control rules are generated and seamlessly distributed to the corresponding defense stages of the network substrate via commonly used protocols. The proposed mitigation schema models the rule assignment to defense stages as a Generalized Assignment Problem. Items, i.e. generic mitigation rules, are assigned to bins, i.e. defense stages, based on capacity constraints and reward values guided by operator policies. Our approach considers reducing the GAP input size to enable reasonable execution of the resulting integer programming formulation. This is accomplished by aggregating malicious IP sources into prefixes and organizing rules into groups. The proposed mechanism is validated in a proof of concept prototype, used to mitigate realistic multi-vector attack scenarios.
机译:在本文中,我们提出了一种通过分布访问控制规则来缓解典型企业网络中检测到的多矢量异常的框架。我们的分布式非专有方法利用了所有设备在攻击路径上提供的功能,从而增强了其缓解风险的能力。这些设备分为不同的防御阶段,网络运营商针对特定的攻击类型表达了他们的防御偏好。我们的机制会自动为每个阶段分配通用缓解规则。随后,生成特定于设备的访问控制规则,并通过常用协议将其无缝分配到网络基板的相应防御阶段。拟议的缓解方案将防御阶段的规则分配建模为广义分配问题。根据运营商策略指导的容量限制和奖励值,将物品(即通用缓解规则)分配给垃圾箱(即防御阶段)。我们的方法考虑减小GAP输入大小,以便合理执行所生成的整数编程公式。这是通过将恶意IP源聚合到前缀并将规则组织到组中来实现的。所提出的机制已在概念证明原型中得到验证,该原型可用于缓解现实的多向量攻击情形。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号