首页> 外文OA文献 >A SPL Framework for Adaptive Deception-based Defense
【2h】

A SPL Framework for Adaptive Deception-based Defense

机译:基于自适应欺骗的防御的spL框架

摘要

In cyber defense, integrated deception mechanisms have been proposed as part of the system operation to enhance security by planting fake resources. The objective is to entice attackers and confuse them in determining the legitimacy of those resources. Although several strategies exist to implement deception in a software system, developing and integrating such solutions are primarily made in an ad-hoc fashion. This hinders reuse and does not consider the operation life cycle management. Additionally, support for adaptive deception is not considered. To alleviate these problems, we propose a framework based on software product lines and aspect-oriented techniques to generate adaptive deception-based defense strategies. We illustrate the feasibility of our approach with an example from the web applications domain, by integrating honeywords into an authentication mechanism to mitigate offline password cracking attacks.
机译:在网络防御中,已提出集成欺骗机制作为系统操作的一部分,以通过种植假资源来增强安全性。目的是诱使攻击者并使他们混淆这些资源的合法性。尽管存在几种在软件系统中实施欺骗的策略,但是开发和集成此类解决方案主要是临时进行的。这阻碍了重用,并且不考虑操作生命周期管理。此外,不考虑支持自适应欺骗。为了缓解这些问题,我们提出了一个基于软件产品线和面向方面技术的框架,以生成基于自适应欺骗的防御策略。通过将蜜语集成到身份验证机制中以减轻离线密码破解攻击,我们以Web应用程序领域的示例为例,说明了我们方法的可行性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号