资源描述:
《拟态防御dhr模型若干问题探讨和性能评估》由会员上传分享,免费在线阅读,更多相关内容在工程资料-天天文库。
1、第1卷第4期信息安全学报Vol.1No.42016年10月JournalofCyberSecurityOct.,2016拟态防御DHR模型若干问题探讨和性能评估扈红超,陈福才,王禛鹏国家数字交换系统工程技术研究中心郑州中国450002摘要针对传统防御技术难以应对未知特征和未知缺陷的攻击,近年来,工业界和学术界尝试发展能够“改变游戏规则”的创新性防御技术。网络空间拟态防御(CMD:CyberspaceMimicDefense)以动态异构冗余(DHR:DynamicalHeterogeneousRedundant)作为核心架构技术。针对信息系统保护的元功能,采用非相似余度设计方法构造多个功能等价
2、的异构执行体;在系统运行期间,动态调度元功能的不同异构执行体在线运行,以阻断攻击者的攻击过程;同时,利用多模判决机制对多个异构执行体的输出结果进行判决,以检测是否发生攻击。本文针对DHR模型的若干问题进行了探讨,给出了一种理论分析方法,并进行了实验仿真,理论分析和仿真结果表明,DHR能够大幅提升攻击者攻击难度,增强信息系统的安全性。关键词动态异构余度;动态调度;异构性;冗余性中图法分类号TN919.21DOI号10.19363/j.cnki.cn10-1380/tn.2016.04.004PerformanceEvaluationsonDHRforCyberspaceMimicDefense
3、HUHongchao,CHENFucai,WANGZhenpengNationalDigitalSwitchingSystemEngineering&TechnologicalR&DCenter,Zhengzhou450002,ChinaAbstractInrecentyears,bothacademiaandindustryhavetriedtodevelopinnovativedefensetechnologies,sinceexist-ingdefensetechnologiesaredifficulttodealwiththeattacksemployingunknownsecuri
4、tyflawsorbackdoors.Startingfromanalyzingtherootcausesofsecurityproblemsincyberspace,thatis,1)securityflaws(holesandthebackdoors)ininformationsystemsareuniversal;2)currentcyberspaceelementsarestaticandhomogeneous,asaresult,thesecurityflawscanbewidelyadopted;3)existingtechniquesaredifficulttocheckand
5、removesecurityflaws.Duetothis,professorWuJiangxingproposedanoveldefenseframework,namelycyberspacemimicdefense(CMD),todefensenetworkattacksemployingunknownsecurityflawsbyintroducingdynamicaldissimilarityredundancymechanism(DHR:dynamicalhet-erogeneousredundant).DHRconstructsseveralfunctionallyequival
6、entvariantsforthemetafunctiontobeprotected,dy-namicallyschedulesseveralvariantstoruninparalleltoblocktheattackingprocess.Atthesametime,itusesmultimodedecisionmechanismtodecidewhichoutputsoftherunningvariantsarecorrectandwhetherattackshaveoccurred.ThispapermainlyfocusesontheevaluationissueofDHR,anda
7、nalyzesitsperformancewithatheoreticalmodel.SimulationsresultsshowthatDHRcansignificantlyimprovethesecurityperformanceofinformationsystems.KeywordsDynamical,heterogeneousandredundant;dynamicalscheduling;hete