期刊文献+
共找到9篇文章
< 1 >
每页显示 20 50 100
On Distributed Object Storage Architecture Based on Mimic Defense 被引量:4
1
作者 Haiyang Yu Hui Li +1 位作者 Xin Yang Huajun Ma 《China Communications》 SCIE CSCD 2021年第8期109-120,共12页
With the advent of the era of big data,cloud computing,Internet of things,and other information industries continue to develop.There is an increasing amount of unstructured data such as pictures,audio,and video on the... With the advent of the era of big data,cloud computing,Internet of things,and other information industries continue to develop.There is an increasing amount of unstructured data such as pictures,audio,and video on the Internet.And the distributed object storage system has become the mainstream cloud storage solution.With the increasing number of distributed applications,data security in the distributed object storage system has become the focus.For the distributed object storage system,traditional defenses are means that fix discovered system vulnerabilities and backdoors by patching,or means to modify the corresponding structure and upgrade.However,these two kinds of means are hysteretic and hardly deal with unknown security threats.Based on mimic defense theory,this paper constructs the principle framework of the distributed object storage system and introduces the dynamic redundancy and heterogeneous function in the distributed object storage system architecture,which increases the attack cost,and greatly improves the security and availability of data. 展开更多
关键词 distributed object storage system mimic defense data security
在线阅读 下载PDF
A Function-Aware Mimic Defense Theory and Its Practice 被引量:1
2
作者 He Jiajun Yuan Yali +3 位作者 Liang Sichu Fu Jiale Zhu Hongyu Cheng Guang 《China Communications》 SCIE CSCD 2024年第8期192-210,共19页
In recent years,network attacks have been characterized by diversification and scale,which indicates a requirement for defense strategies to sacrifice generalizability for higher security.As the latest theoretical ach... In recent years,network attacks have been characterized by diversification and scale,which indicates a requirement for defense strategies to sacrifice generalizability for higher security.As the latest theoretical achievement in active defense,mimic defense demonstrates high robustness against complex attacks.This study proposes a Function-aware,Bayesian adjudication,and Adaptive updating Mimic Defense(FBAMD)theory for addressing the current problems of existing work including limited ability to resist unknown threats,imprecise heterogeneous metrics,and over-reliance on relatively-correct axiom.FBAMD incorporates three critical steps.Firstly,the common features of executors’vulnerabilities are obtained from the perspective of the functional implementation(i.e,input-output relationships extraction).Secondly,a new adjudication mechanism considering Bayes’theory is proposed by leveraging the advantages of both current results and historical confidence.Furthermore,posterior confidence can be updated regularly with prior adjudication information,which provides mimic system adaptability.The experimental analysis shows that FBAMD exhibits the best performance in the face of different types of attacks compared to the state-of-the-art over real-world datasets.This study presents a promising step toward the theo-retical innovation of mimic defense. 展开更多
关键词 Bayesian theory CONFIDENCE functional implementation mimic defense
在线阅读 下载PDF
Research on Cyberspace Mimic Defense Based on Dynamic Heterogeneous Redundancy Mechanism 被引量:1
3
作者 Junjie Xu 《Journal of Computer and Communications》 2021年第7期1-7,共7页
With the rapid growth of network technology, the methods and types of cyber-attacks are increasing rapidly. Traditional static passive defense technologies focus on external security and known threats to the target sy... With the rapid growth of network technology, the methods and types of cyber-attacks are increasing rapidly. Traditional static passive defense technologies focus on external security and known threats to the target system and cannot resist advanced persistent threats. To solve the situation that cyberspace security is easy to attack and difficult to defend, Chinese experts on cyberspace security proposed an innovative theory called mimic defense, it is an active defense technology that employs “Dynamic, Heterogeneous, Redundant” architecture to defense attacks. This article first briefly describes the classic network defense technology and Moving Target Defense (MTD). Next, it mainly explains in detail the principles of the mimic defense based on the DHR architecture and analyzes the attack surface of DHR architecture. This article also includes applications of mimic defense technology, such as mimic routers, and mimic web defense systems. Finally, it briefly summarizes the existing research on mimic defense, expounds the problems that need to be solved in mimic defense, and looks forward to the future development of mimic defense. 展开更多
关键词 Cyberspace mimic defense Dynamic Heterogeneous Redundancy Structure defense Technology Network Security
在线阅读 下载PDF
Research on the Key Techniques of TCP Protocol Normalization for Mimic Defense Architecture
4
作者 Mingxing Zhu Yansong Wang +4 位作者 Ruyun Zhang Tianning Zhang Heyuan Li Hanguang Luo Shunbin Li 《Journal on Internet of Things》 2021年第3期99-107,共9页
The Mimic Defense(MD)is an endogenous security technology with the core technique of Dynamic Heterogeneous Redundancy(DHR)architecture.It can effectively resist unknown vulnerabilities,backdoors,and other security thr... The Mimic Defense(MD)is an endogenous security technology with the core technique of Dynamic Heterogeneous Redundancy(DHR)architecture.It can effectively resist unknown vulnerabilities,backdoors,and other security threats by schedule strategy,negative feedback control,and other mechanisms.To solve the problem that Cyber Mimic Defense devices difficulty of supporting the TCP protocol.This paper proposes a TCP protocol normalization scheme for DHR architecture.Theoretical analysis and experimental results show that this scheme can realize the support of DHR-based network devices to TCP protocol without affecting the security of mimicry defense architecture. 展开更多
关键词 mimic defense TCP protocol NORMALIZATION
在线阅读 下载PDF
Key-area cyberspace mimic defense against data-oriented attacks
5
作者 Ping Chen Jin Wei +1 位作者 Zhuyang Yu Jiwei Chen 《Security and Safety》 2025年第2期71-89,共19页
As modern systems widely deploy protective measures for control data in memory,such as Control-Flow Integrity(CFI),attackers'ability to manipulate control data is greatly restricted.Consequently,attackers are turn... As modern systems widely deploy protective measures for control data in memory,such as Control-Flow Integrity(CFI),attackers'ability to manipulate control data is greatly restricted.Consequently,attackers are turning to opportunities to manipulate non-control data in memory(known as Data-Oriented Attacks,or DOAs),which have been proven to pose significant security threats to memory.However,existing techniques to mitigate DOAs often introduce significant overhead due to the indiscriminate protection of a large range of data objects.To address this challenge,this paper adopts a Cyberspace Mimic Defense(CMD)strategy,a generic framework for addressing endogenous security vulnerabilities,to prevent attackers from executing DOAs using known or unknown security flaws.Specifically,we introduce a formalized expression algorithm that assesses whether DOA attackers can construct inputs to exploit vulnerability points.Building on this,we devise a key-area CMD strategy that modifies the coded pathway from input to the vulnerability point,thereby effectively thwarting the activation of the vulnerability.Finally,our experiments on real-world applications and simulation demonstrate that the key-area CMD strategy can effectively prevent DOAs by selectively diversifying parts of the program code. 展开更多
关键词 Cyberspace mimic defense Data-oriented attacks Large language model
原文传递
Security-as-a-Service with Cyberspace Mimic Defense Technologies in Cloud
6
作者 Junchao Wang Jianmin Pang Jin Wei 《国际计算机前沿大会会议论文集》 2021年第2期129-138,共10页
Users usually focus on the application-level requirements which are quite friendly and direct to them.However,there are no existing tools automating the application-level requirements to infrastructure provisioning an... Users usually focus on the application-level requirements which are quite friendly and direct to them.However,there are no existing tools automating the application-level requirements to infrastructure provisioning and application deployment.Although some security issues have been solved during the development phase,the undiscovered vulnerabilities remain hidden threats to the application’s security.Cyberspace mimic defense(CMD)technologies can help to enhance the application’s security despite the existence of the vulnerability.In this paper,the concept of SECurity-as-a-Service(SECaaS)is proposed with CMD technologies in cloud environments.The experiment on it was implemented.It is found that the application’s security is greatly improved to meet the user’s security and performance requirements within budgets through SECaaS.The experimental results show that SECaaS can help the users to focus on application-level requirements(monetary costs,required security level,etc.)and automate the process of application orchestration. 展开更多
关键词 Cyberspace mimic defense Software diversity Security-as-a-Service Multi-compiler Application deployment
原文传递
Dynamic defenses in cyber security:Techniques,methods and challenges Author links open overlay panel 被引量:13
7
作者 Yu Zheng Zheng Li +1 位作者 Xiaolong Xu Qingzhan Zhao 《Digital Communications and Networks》 SCIE CSCD 2022年第4期422-435,共14页
Driven by the rapid development of the Internet of Things,cloud computing and other emerging technologies,the connotation of cyberspace is constantly expanding and becoming the fifth dimension of human activities.Howe... Driven by the rapid development of the Internet of Things,cloud computing and other emerging technologies,the connotation of cyberspace is constantly expanding and becoming the fifth dimension of human activities.However,security problems in cyberspace are becoming serious,and traditional defense measures(e.g.,firewall,intrusion detection systems,and security audits)often fall into a passive situation of being prone to attacks and difficult to take effect when responding to new types of network attacks with a higher and higher degree of coordination and intelligence.By constructing and implementing the diverse strategy of dynamic transformation,the configuration characteristics of systems are constantly changing,and the probability of vulnerability exposure is increasing.Therefore,the difficulty and cost of attack are increasing,which provides new ideas for reversing the asymmetric situation of defense and attack in cyberspace.Nonetheless,few related works systematically introduce dynamic defense mechanisms for cyber security.The related concepts and development strategies of dynamic defense are rarely analyzed and summarized.To bridge this gap,we conduct a comprehensive and concrete survey of recent research efforts on dynamic defense in cyber security.Specifically,we firstly introduce basic concepts and define dynamic defense in cyber security.Next,we review the architectures,enabling techniques and methods for moving target defense and mimic defense.This is followed by taxonomically summarizing the implementation and evaluation of dynamic defense.Finally,we discuss some open challenges and opportunities for dynamic defense in cyber security. 展开更多
关键词 Cyber security Dynamic defense Moving target defense mimic defense
在线阅读 下载PDF
MimicCloudSim:An Environment for Modeling and Simulation of Mimic Cloud Service 被引量:4
8
作者 Liming Pu Jiangxing Wu +2 位作者 Hailong Ma Yuhang Zhu Yingle Li 《China Communications》 SCIE CSCD 2021年第1期212-221,共10页
In recent years,an increasing number of application services are deployed in the cloud.However,the cloud platform faces unknown security threats brought by its unknown vulnerabilities and backdoors.Many researchers ha... In recent years,an increasing number of application services are deployed in the cloud.However,the cloud platform faces unknown security threats brought by its unknown vulnerabilities and backdoors.Many researchers have studied the Cyber Mimic Defense(CMD)technologies of the cloud services.However,there is a shortage of tools that enable researchers to evaluate their newly proposed cloud service CMD mechanisms,such as scheduling and decision mechanisms.To fill this gap,we propose MimicCloudSim as a mimic cloud service simulation system based on the basic functionalities of CloudSim.MimicCloudSim supports the simulation of dynamic heterogeneous redundancy(DHR)structure which is the core architecture of CMD technology,and provides an extensible interface to help researchers implement new scheduling and decision mechanisms.In this paper,we firstly describes the architecture and implementation of MimicCloudSim,and then discusses the simulation process.Finally,we demonstrate the capabilities of MimicCloudSim by using a decision mechanism.In addition,we tested the performance of MimicCloudSim,the conclusion shows that MimicCloudSim is highly scalable. 展开更多
关键词 cyber mimic defense mimic cloud service SIMULATION dynamic heterogeneous redundancy
在线阅读 下载PDF
Output difference feedback and system benefit control based dynamic heterogeneous redundancy architecture
9
作者 Sisi SHAO Zhibo HE +7 位作者 Shangdong LIU Weili ZHANG Fei WU Fukang ZENG Jun ZUO Longfei ZHOU Yukun NIU Yimu JI 《Frontiers of Information Technology & Electronic Engineering》 2025年第8期1279-1292,共14页
Mimic active defense technology effectively disrupts attack routes and reduces the probability of successful attacks by using a dynamic heterogeneous redundancy(DHR)architecture.However,current approaches often overlo... Mimic active defense technology effectively disrupts attack routes and reduces the probability of successful attacks by using a dynamic heterogeneous redundancy(DHR)architecture.However,current approaches often overlook the adaptability of the adjudication mechanism in complex and variable network environments,focusing primarily on system security while neglecting performance considerations.To address these limitations,we propose an output difference feedback and system benefit control based DHR architecture.This architecture introduces an adjudication mechanism based on output difference feedback,which enhances adaptability by considering the impact of each executor's output deviation on the global decision.Additionally,the architecture incorporates a scheduling strategy based on system benefit,which models the quality of service and switching overhead as a bi-objective optimization problem,balancing security with reduced computational costs and system overhead.Simulation results demonstrate that our architecture improves adaptability towards different network environments and effectively reduces both the attack success rate and average failure rate. 展开更多
关键词 mimic defense Adjudication mechanism Scheduling strategy Executor output difference System benefit
原文传递
上一页 1 下一页 到第
使用帮助 返回顶部