首页> 外文会议>IEEE Secure Development Conference >Active Deception Framework: An Extensible Development Environment for Adaptive Cyber Deception
【24h】

Active Deception Framework: An Extensible Development Environment for Adaptive Cyber Deception

机译:主动欺骗框架:自适应网络欺骗的可扩展开发环境

获取原文

摘要

Cyber deception provides a proactive cyber defense that can reverse the asymmetry in cyber warfare through confusing, misleading, or diverting attackers to false goals. However, developing and deploying adaptive cyber deception techniques in real-life operational networks is an extremely complex and time-consuming task due to the extensive efforts required to implement the underlying network infrastructure configuration functions that are necessary to support active cyber deception operations, including observing, planning, and deploying honey resources at real-time. Therefore, developers in this field often spend significant time and effort building such infrastructural functions rather than focusing on developing sophisticated strategies for cyber deception applications.In this paper, we developed an active cyber deception framework (ADF) that provides an extensible rich API and synthesis engine for developing advanced cyber deception applications. The API can be used to observe adversary actions, compose multi-strategy deception plans, and ensure safe yet quick deployment of deception plans by automatically managing the network configuration and operational tasks. In addition, ADF provides deception as a service by automatic orchestration of deception planning and deployment with minimal human involvement. We implemented our deception framework using the OpenDaylight Software-defined networking controller. We evaluated ADF using various case studies that demonstrate the rapid and cost-effective deployment of advanced application of active deception on real networks within a few seconds.
机译:网络欺骗提供了一个主动的网络防御,可以通过混淆,误导或将攻击者转移到虚假目标来逆转网络战中的不对称。然而,由于实现了支持主动网络欺骗操作所需的底层网络基础设施配置功能所需的广泛努力,开发和部署在现实操作网络中的自适应网络欺骗技术是一个非常复杂和耗时的任务。 ,实时规划和部署蜂蜜资源。因此,该领域的开发人员经常花费重要的时间和精力,建立这种基础设施功能,而不是专注于开发对网络欺骗应用的复杂策略。在本文中,我们开发了一个积极的网络欺骗框架(ADF),提供了可扩展的丰富API和合成发动机开发先进的网络欺骗应用。 API可用于遵守对手的行动,撰写多策略欺骗计划,并通过自动管理网络配置和操作任务确保安全但快速地部署欺骗计划。此外,ADF通过自动编排欺骗计划和部署,以最小的人类参与提供欺骗作为服务。我们使用OpenDaylight软件定义的网络控制器实现了我们的欺骗框架。我们使用各种案例研究评估了ADF,展示了几秒钟内在真实网络上进行了快速和成本致力于在实际网络上进行高级应用的快速和成本效益部署。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号