摘要
针对现有网络诱骗技术需要过多人工参与且无法保障诱骗效率和准确度的问题,提出了面向自律计算的具有容侵特性的主动诱骗算法,分为服务移植和诱骗机制2个阶段.服务移植主要完成可疑信息重定向和可信信息访问恢复,实现目标系统的安全隔离;诱骗子网主要实现攻击信息的主动诱骗、特征分析和自律联想学习.仿真实验结果表明,在同等入侵条件下,加载ADAIT算法的系统平均事务响应时间缩短38.96%,吞吐率提高59.43%,每秒HTTP响应数增加13.25%,服务器的关键性能明显提升.
Current network deception technology needs manual intervention,yet cannot ensure deception is efficient and effective.An automatic deception algorithm using autonomic intrusion tolerance(ADAIT) was proposed.The functions were divided into two stages,the first service transplant and the second deception mechanisms.Service transplant completes retargeting of suspicious information and recovering of legal access,implementing security isolation for the object system.Deception mechanisms provide automatic deception,feature analysis and autonomic associative study of attack information.The simulation results showed that with the help of ADAIT,given the same intrusions,the average transaction response time was reduced by 38.96%,throughput was enhanced by 59.43%,and the number of HTTP responses per second was increased by 13.25%.These key indicators of server performance were obviously improved.
出处
《哈尔滨工程大学学报》
EI
CAS
CSCD
北大核心
2010年第8期1048-1053,共6页
Journal of Harbin Engineering University
基金
国家自然科学基金资助项目(60973027)
中央高校基本科研业务费专项资金(HEUF100601)
黑龙江省科技攻关基金资助项目(GC09A104)
哈尔滨市科技创新人才研究基金资助项目(2010RFQXG026)
关键词
自律容侵
主动诱骗
服务移植
诱骗子网
联想学习
autonomic intrusion tolerance
automatic deception
service transplant
trapping subnetl
associative study