检索规则说明:AND代表“并且”;OR代表“或者”;NOT代表“不包含”;(注意必须大写,运算符两边需空一格)
检 索 范 例 :范例一: (K=图书馆学 OR K=情报学) AND A=范并思 范例二:J=计算机应用与软件 AND (U=C++ OR U=Basic) NOT M=Visual
作 者:赵金龙 张国敏 邢长友 宋丽华 宗祎本 ZHAO Jin-long;ZHANG Guo-min;XING Chang-you;SONG Li-hua;ZONG Yi-ben(Command&Control Engineering College,Army Engineering University of PLA,Nanjing 210007,China;Unit 61789 of PLA,Shanghai 200000,China)
机构地区:[1]中国人民解放军陆军工程大学指挥控制工程学院,南京210007 [2]中国人民解放军61789部队,上海200000
出 处:《计算机科学》2020年第12期304-310,共7页Computer Science
基 金:国家自然科学基金(61379149,61772271);国家博士后科学基金项目(2017M610286)。
摘 要:静态配置的网络主机信息在面对攻击者侦察时易于暴露,进而带来了严重的安全隐患。主机地址跳变及部署虚假节点等欺骗方法能够扰乱攻击者对网络的认知,增加其网络侦察的难度。但如何高效地利用这些手段来对抗攻击者的侦察行为仍存在诸多困难。为此,在对攻防双方行为进行建模描述的基础上,提出了一种高效的自适应欺骗防御机制(Self-adaptive Deception Method,SADM)来应对网络侦察。SADM结合网络侦察过程中攻防双方多阶段持续对抗的特点,以资源约束下防御方的综合收益最大化为目标进行建模,并在此基础上通过启发式方法进行自适应防御决策,以快速应对攻击者的多样化扫描行为。仿真实验结果表明,SADM能够有效延缓攻击者的探测速度,在保证防护效果的同时降低部署欺骗场景的代价。The statically configured network host information is easy to be exposed in the face of network reconnaissance,which brings serious security risks.Deception methods such as host address mutation and deployment of fake nodes can disrupt attac-ker’s awareness of the network and increase the difficulty of reconnaissance.However,there are still many challenges in using these methods to counter attacker’s reconnaissance behavior effectively.For this reason,by modeling the behaviors of both attaker and defender,an efficient self-adaptive deception defense mechanism SADM(Self-adaptive Deception Method)is proposed.SADM considers the characteristics of the multi-stage continuous confrontation between attacker and defender in the network reconnaissance process,modeling with the goal of maximizing the defender’s accumulative payoffs under cost constraints,and then makes adaptive defense decisions through heuristic methods,to respond quickly to attacker's diverse scanning behavior.The simulation experiment results show that SADM can effectively delay the attacker's detection speed and reduce the cost of deploying deception scenarios while ensuring the defense effect.
分 类 号:TP393[自动化与计算机技术—计算机应用技术]
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在链接到云南高校图书馆文献保障联盟下载...
云南高校图书馆联盟文献共享服务平台 版权所有©
您的IP:216.73.216.33