首页> 外文期刊>Communications Surveys & Tutorials, IEEE >A Survey of Moving Target Defenses for Network Security
【24h】

A Survey of Moving Target Defenses for Network Security

机译:网络安全移动目标防御调查

获取原文
获取原文并翻译 | 示例

摘要

Network defenses based on traditional tools, techniques, and procedures (TTP) fail to account for the attacker’s inherent advantage present due to the static nature of network services and configurations. To take away this asymmetric advantage, Moving Target Defense (MTD) continuously shifts the configuration of the underlying system, in turn reducing the success rate of cyberattacks. In this survey, we analyze the recent advancements made in the development of MTDs and highlight (1) how these defenses can be defined using common terminology, (2) can be made more effective with the use of artificial intelligence techniques for decision making, (3) be implemented in practice and (4) evaluated. We first define an MTD using a simple and yet general notation that captures the key aspects of such defenses. We then categorize these defenses into different sub-classes depending on what they move, when they move and how they move. In trying to answer the latter question, we showcase the use of domain knowledge and game-theoretic modeling can help the defender come up with effective and efficient movement strategies. Second, to understand the practicality of these defense methods, we discuss how various MTDs have been implemented and find that networking technologies such as Software Defined Networking and Network Function Virtualization act as key enablers for implementing these dynamic defenses. We then briefly highlight MTD test-beds and case-studies to aid readers who want to examine or deploy existing MTD techniques. Third, our survey categorizes proposed MTDs based on the qualitative and quantitative metrics they utilize to evaluate their effectiveness in terms of security and performance. We use well-defined metrics such as risk analysis and performance costs for qualitative evaluation and metrics based on Confidentiality, Integrity, Availability (CIA), attack representation, QoS impact, and targeted threat models for quantitative evaluation. Finally, we show that our categorization of MTDs is effective in identifying novel research areas and highlight directions for future research.
机译:基于传统工具,技术和程序(TTP)的网络防御未能因网络服务和配置的静态性质而导致攻击者的固有优势。要带走这种不对称的优势,移动目标防御(MTD)连续转换底层系统的配置,反过来降低了网络内的成功率。在这项调查中,我们分析了MTDS发展中提出的最新进步,并突出了(1)如何使用普通术语来定义这些防御,(2)可以更有效地利用人工智能技术进行决策,( 3)在实践中实施和(4)评估。我们首先使用简单且一般的符号来定义MTD,捕获这些防御的关键方面。然后,我们将这些防御分为不同的子类别,具体取决于什么 他们搬家,时 他们搬家了如何 他们搬家了。在试图回答后一种问题时,我们展示了域知识和游戏理论建模可以帮助防御者提出有效和有效的运动策略。其次,要了解这些防御方法的实用性,我们讨论了如何实施各种MTD,并发现软件定义的网络和网络功能虚拟化等网络技术充当用于实现这些动态防御的关键推动力。然后,我们简要介绍了MTD测试床和案例研究,以帮助想要检查或部署现有MTD技术的读者。第三,我们的调查根据他们利用的定性和定量指标分类了拟议的MTDS,以评估其在安全性和性能方面的有效性。我们使用明确定义的指标,例如基于机密性,完整性,可用性(CIA),攻击表示,QoS影响以及针对定量评估的定性评估和指标的风险分析和性能成本。最后,我们表明,我们的MTDs分类是有效地识别新型研究领域,并突出未来研究方向。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号