首页> 外文期刊>Computers & Security >Network moving target defense technique based on collaborative mutation
【24h】

Network moving target defense technique based on collaborative mutation

机译:基于协同变异的网络移动目标防御技术

获取原文
获取原文并翻译 | 示例
           

摘要

Moving target defense is emerging as a research hotspot in addressing the asymmetric situation between attack and defense in cyberspace, and network mutation is one of the key technologies. In order to improve the defensive benefit brought by network mutation and ensure the service quality of network systems, a novel network moving target defense technique based on collaborative mutation is proposed. In order to maximize the defensive benefit, collaborative mutation and self-learning mutation strategy selection are proposed. In collaborative mutation, end-point mutation and routing mutation are adopted collaboratively so as to improve mutation space. Mutation strategy selection based on adversary strategy awareness is designed by using hypothesis test to self-learn malicious reconnaissance strategies, thus maximizing the unpredictability of network mutation. Then, the satisfiability modulo theories and mutation collision avoidance are used to improve availability in networks with limited resources. Satisfiability modulo theory is used to formally describe the overhead constraints of the mutation, so as to ensure the quality of service. Besides, mutation collision avoidance based on network fingerprinting is designed to eliminate mutation collision, thus improving the availability of the proposed method. Finally, theoretical and experimental analyses demonstrate that the proposed technique can effectively resist different types of malicious reconnaissance strategies and ensure low mutation overhead at the same time.
机译:移动目标防御已成为解决网络空间攻击与防御之间不对称情况的研究热点,网络突变是关键技术之一。为了提高网络变异带来的防御效益,保证网络系统的服务质量,提出了一种基于协同变异的新型网络移动目标防御技术。为了最大化防御利益,提出了协同突变和自学习突变策略的选择。在协同突变中,端点突变和路由突变被协同采用,以改善突变空间。利用假设检验设计自学习恶意侦察策略,设计了基于对抗策略意识的变异策略选择,从而最大化了网络变异的不可预测性。然后,可满足性模理论和避免突变冲突被用于提高资源有限的网络中的可用性。可满足性模理论被用来正式描述突变的开销约束,从而确保服务质量。此外,设计了一种基于网络指纹的避免突变冲突的方法,以消除突变冲突,从而提高了该方法的可用性。最后,理论和实验分析表明,所提出的技术可以有效地抵抗不同类型的恶意侦察策略,并同时确保较低的突变开销。

著录项

  • 来源
    《Computers & Security》 |2017年第9期|51-71|共21页
  • 作者单位

    China National Digital Switching System Engineering & Technological Research Center, Zhengzhou 450001, China,Henan Key Laboratory of Information Security, Zhengzhou 450001, China;

    China National Digital Switching System Engineering & Technological Research Center, Zhengzhou 450001, China,Henan Key Laboratory of Information Security, Zhengzhou 450001, China;

    China National Digital Switching System Engineering & Technological Research Center, Zhengzhou 450001, China,Henan Key Laboratory of Information Security, Zhengzhou 450001, China;

    China National Digital Switching System Engineering & Technological Research Center, Zhengzhou 450001, China,Henan Key Laboratory of Information Security, Zhengzhou 450001, China;

  • 收录信息 美国《科学引文索引》(SCI);美国《工程索引》(EI);
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Network collaborative mutation; Network fingerprinting; Satisfiability modulo theories; Mutation collision avoidance; Software-defined network;

    机译:网络协作突变;网络指纹;可满足性模理论;避免突变冲突;软件定义的网络;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号