...
首页> 外文期刊>Telecommunication systems: Modeling, Analysis, Design and Management >Toward an integrated dynamic defense system for strategic detecting attacks in cloud networks using stochastic game
【24h】

Toward an integrated dynamic defense system for strategic detecting attacks in cloud networks using stochastic game

机译:朝着云网络中的战略检测攻击综合动态防御系统,使用随机游戏

获取原文
获取原文并翻译 | 示例
           

摘要

In a complex network as a cloud computing environment, security is becoming increasingly based on deception techniques. To date, the static nature of cyber networks offers to adversaries good opportunities to systematically study the network environment, launch a cyber-attack effortlessly and wide-spread and finally defeat the target system. In order to resolve the limitations of the traditional security measures as intrusion prevention or detection systems, firewall, access list, etc., which did not change the attack surface and cannot avoid zero-days attacks, technics that provide dynamic defense, such virtual machine migration and honeypot should be deployed. Despite this, with a virtual machine migration technique, not all virtual machines' migration between servers enhances security considerably. In this paper, we propose an integrated defense system combining virtual machine migration and honeypot. The effectiveness of the proposed system is discussed in terms of security policies. In addition, our proposed model determines the potential attack paths quantitatively then classifies them into two sub-sets: attack paths explored only and attack paths explored and exploited based on the black box intrusion steps. Thus, to model the interaction attacker-defender, the attack graph combined with the stochastic game theory is used. Finally, we carry out some numerical results to demonstrate the effectiveness of the proposed security game model.
机译:在一个复杂的网络中作为云计算环境,安全性正在越来越基于欺骗技术。迄今为止,网络网络的静态性质提供了对系统研究网络环境的良好机会,毫不费力地和广泛传播的网络攻击,最终击败目标系统。为了解决传统安全措施的限制作为入侵预防或检测系统,防火墙,访问列表等,该系统没有改变攻击面,无法避免零天攻击,提供动态防御的技术,这些虚拟机应部署迁移和蜜罐。尽管如此,对于虚拟机迁移技术,并非所有虚拟机之间的所有虚拟机在服务器之间的迁移都会提高安全性。在本文中,我们提出了一种结合虚拟机迁移和蜜罐的综合防御系统。在安全政策方面讨论了拟议系统的有效性。此外,我们的建议模型定量地确定了潜在的攻击路径,然后将它们分为两个子集:仅探索的攻击路径,并根据黑盒入侵步骤探索和利用攻击路径。因此,为了模拟互动攻击者 - 后卫,使用攻击图与随机博弈论相结合。最后,我们对展示建议的安全游戏模型的有效性进行了一些数值结果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号