首页> 外文期刊>Nature reviews neuroscience >Design and implementation of a novel enterprise network defense system bymaneuveringmulti-dimensional network properties
【24h】

Design and implementation of a novel enterprise network defense system bymaneuveringmulti-dimensional network properties

机译:通过ManumeringMulti-Vile网络属性设计和实现新型企业网络防御系统

获取原文
获取原文并翻译 | 示例
           

摘要

Although the perimeter security model works well enough when all internal hosts are credible, it is becoming increasingly difficult to enforce as companies adopt mobile and cloud technologies, i.e., the rise of bring your own device (BYOD). It is observed that advanced targeted cyber-attacks usually follow a cyber kill chain; for instance, advanced targeted attacks often rely on network scanning techniques to gather information about potential targets. In response to this attack method, we propose a novel approach, i.e., an isolating and dynamic cyber defense, which cuts these potential chains to reduce the cumulative availability of the gathered information. First, we build a zero-trust network environment through network isolation, and then multiple network properties are maneuvered so that the host characteristics and locations needed to identify vulnerabilities cannot be located. Second, we propose a software-defined proactive cyber defense solution (SPD) for enterprise networks and design a general framework to strategically maneuver the IP address, network port, domain name, and path, while limiting the performance impact on the benign network user. Third, we implement our SPD proof-of-concept system over a software-defined network controller (OpenDaylight). Finally, we build an experimental platform to verify the system's ability to prevent scanning, eavesdropping, and denial-of-service attacks. The results suggest that our system can significantly reduce the availability of network reconnaissance scan information, block network eavesdropping, and sharply increase the cost of cyber-attacks.
机译:虽然周边安全模型很好地运行,但当所有内部主机都是可信的时,由于公司采用移动和云技术,即提升您自己的设备(BYOD)的崛起,它变得越来越困难。观察到,先进的目标网络攻击通常遵循网络杀戮链;例如,高级目标攻击通常依赖于网络扫描技术来收集有关潜在目标的信息。响应于这种攻击方法,我们提出了一种新的方法,即隔离和动态网络防御,从而减少了这些潜在链以减少收集信息的累积可用性。首先,我们通过网络隔离构建零信任网络环境,然后进行多个网络属性,以便无法找到识别漏洞所需的主机特性和位置。其次,我们为企业网络提出了一个软件定义的主动网络防御解决方案(SPD),并将一般框架设计为战略性地操纵IP地址,网络端口,域名和路径,同时限制对良性网络用户的性能影响。第三,我们在软件定义的网络控制器(OpenDaylight)上实施我们的SPD概念验证系统。最后,我们建立一个实验平台,以验证系统防止扫描,窃听和拒绝服务攻击的能力。结果表明,我们的系统可以显着降低网络侦察扫描信息的可用性,阻止网络窃听,并急剧增加网络攻击的成本。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号