期刊文献+

基于网络安全态势感知的主动防御技术研究 被引量:49

An active defense technique based on network security awareness
在线阅读 下载PDF
导出
摘要 网络主动防御作为突破传统被动防御瓶颈的关键技术正成为网络信息安全领域的研究热点。针对网络主动防御缺乏防御针对性的问题,提出了基于网络安全态势感知的主动防御技术。首先,设计了基于扫描流量熵的网络安全态势感知方法,通过判别恶意敌手的扫描策略指导主动防御策略的选取,以增强防御的针对性。在此基础上,提出了基于端信息转换的主动防御机制,通过转换网络端信息实现网络拓扑结构的动态随机改变,从而达到增加网络攻击难度和成本的目的。理论与实验验证了该技术可有效针对不同类型的扫描策略实施高效的主动防御。 As a key technique to break through the bottleneck of passive defense,network active defense becomes a hotspot in network information security.To solve the blindness problem of hopping mechanism in the course of network defense,we propose a novel active defense mechanism based on network security situation awareness.Firstly,a network security situational awareness method based on scanning flow entropy is designed,which enhances the targeted defense by discriminating the adversary scanning strategy.Based on this,an active defense mechanism based on end-point information transformation is proposed.It can increase the difficulty and the cost of attacks by randomly changing network topology dynamically through transforming end-point information.Theoretical and experimental analyses show that the proposed active defense technique can be employed efficiently under different scanning strategies.
作者 刘世文 马多耀 雷程 尹少东 张红旗 LIU Shi-wen;MA Duo-yao;LEI Cheng;YIN Shao-dong;ZHANG Hong-qi(College of Cryptography Engineering,PLA Information Engineering University,Zhengzhou 450001;Key Laboratory of Urban ITS Technology Optimization and Integration,Ministry of Public Security PRC,Hefei 230001;State Key Laboratory of Information Security,Institute of Information Engineering,Chinese Academy of Sciences,Beijing 100093;Anhui Keli Information Industry Co.,Ltd,Hefei 230001;Henan Key Laboratory of Information Security,Zhengzhou 450001,China)
出处 《计算机工程与科学》 CSCD 北大核心 2018年第6期1054-1061,共8页 Computer Engineering & Science
基金 国家973计划(2011CB311801) 国家863计划(2012AA012704 2015AA016106) 郑州市科技领军人才基金(131PLKRC644) 中国科学院先导专项基金(XDA06010701)
关键词 网络安全态势感知 扫描流量熵 软件定义网络 主动防御 端信息转换 network security situation awareness scanning flow entropy software defined network active defense end-point information transformation
  • 相关文献

参考文献4

二级参考文献19

  • 1苏威积,赵海,徐野,张文波.基于hops的Internet复杂网络分割度分析[J].通信学报,2005,26(9):1-8. 被引量:6
  • 2谢希仁.计算机网络(第五版)[M].北京:电子工业出版社,2006.
  • 3YOOK S H,JEONG H, BARABASI A L. Modeling the Internet's large-scale topology[J].Proceedings of the National Academy of Sci-ences,2002,99(21):13382-13386.
  • 4ALBERT R,JEONG H,BARAB,/S1 A L.Internet:Diameter of the world-wide web [J] .Nature, 1999,401 (6749): 130-131.
  • 5PASTOR-SATORRAS R,VESPIGNANI A,Evolution and Structure of the Intemet: A Statistical Physics Approach[M].Cambridge University Press, 2007.
  • 6MILLS D L.Intemet Delay Experiments[R]. RFC-889, 1983, 12.
  • 7MOON S B, KUROSE J, SKELLY P. Correlation of packet delay, and loss in the Intemet[R]. Department of Computer Science, University of Massachusetts, Amherst, MA01003, 1998: 98-11.
  • 8ACHARYA A,SALTZ J.A study of Intemet round2trip delay[R]. Technical Report CS2TR23736,University of Maryland, College Park 20742, 1997.
  • 9BRADLEY H, MARINA F, DANIEL J. Distance metrics in the Inter- net[A]. Proceedings of the IEEE International Telecommunications Symposium 2002 [C].Natal,Brazil,2002.200-202.
  • 10CAIDA Ark Project [EB/OL]. http://www.CAIDA.org/projeets/Ark/.

共引文献127

同被引文献471

引证文献49

二级引证文献314

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部