Enhancement of service function chain(SFC)security ability by composing virtual network functions(VNFs)and allocating resources considering their security attributes can address the vulnerability threats in cloud envi...Enhancement of service function chain(SFC)security ability by composing virtual network functions(VNFs)and allocating resources considering their security attributes can address the vulnerability threats in cloud environments,which is an important means of attempting to secure SFCs at the deployment stage.However,existing works do not consider the vulnerability correlation of the multi-step attack chains when completing SFC deployment based on trustworthiness.This results in existing security orchestration methods ignoring the differences in trustworthiness among network entities and focusing only on local trust optimization;these steps effectively disrupt the attack chains to secure SFCs.In this article,an innovative hierarchical trust model is proposed to assess the differentiated trustworthiness among network entities caused by vulnerability correlation.On the basis of trustworthiness assessment,both virtual trust of VNF combinations at the SFC composition stage and physical trust of physical node(PN)selections at the SFC placement stage are globally considered to disrupt the attack chains in SFCs as much as possible.To this end,the security-aware and cost-efficient SFC composition and placement(SCSCP)problem is formulated as an integer linear programming(ILP)problem,which is NP-hard.To tackle the SCSCP problem,the joint trust and cost global optimization(JTCGO)algorithm is proposed to dynamically update the trustworthiness and globally flnd the SFC deployment solutions including the VNF combination schemes and PN selection schemes.Simulation results demonstrate that our proposed algorithm can provide the optimal SFC deployment solutions for requests and can guarantee the SFC trustworthiness at a controllable cost,thereby protecting SFCs from network attacks in complex security environments.展开更多
Aspects of human behavior in cyber security allow more natural security to the user. This research focuses the appearance of anticipating cyber threats and their abstraction hierarchy levels on the mental picture leve...Aspects of human behavior in cyber security allow more natural security to the user. This research focuses the appearance of anticipating cyber threats and their abstraction hierarchy levels on the mental picture levels of human. The study concerns the modeling of the behaviors of mental states of an individual under cyber attacks. The mental state of agents being not observable, we propose a non-stationary hidden Markov chain approach to model the agent mental behaviors. A renewal process based on a nonparametric estimation is also considered to investigate the spending time in a given mental state. In these approaches, the effects of the complexity of the cyber attacks are taken into account in the models.展开更多
基金Project supported by the National Key Research and Development Plan of China(No.2022YFB2902204)the Key Research and Development Project of Henan Province(No.231111211000)the Top Talent Training Project of Henan Province(No.244500510012)。
文摘Enhancement of service function chain(SFC)security ability by composing virtual network functions(VNFs)and allocating resources considering their security attributes can address the vulnerability threats in cloud environments,which is an important means of attempting to secure SFCs at the deployment stage.However,existing works do not consider the vulnerability correlation of the multi-step attack chains when completing SFC deployment based on trustworthiness.This results in existing security orchestration methods ignoring the differences in trustworthiness among network entities and focusing only on local trust optimization;these steps effectively disrupt the attack chains to secure SFCs.In this article,an innovative hierarchical trust model is proposed to assess the differentiated trustworthiness among network entities caused by vulnerability correlation.On the basis of trustworthiness assessment,both virtual trust of VNF combinations at the SFC composition stage and physical trust of physical node(PN)selections at the SFC placement stage are globally considered to disrupt the attack chains in SFCs as much as possible.To this end,the security-aware and cost-efficient SFC composition and placement(SCSCP)problem is formulated as an integer linear programming(ILP)problem,which is NP-hard.To tackle the SCSCP problem,the joint trust and cost global optimization(JTCGO)algorithm is proposed to dynamically update the trustworthiness and globally flnd the SFC deployment solutions including the VNF combination schemes and PN selection schemes.Simulation results demonstrate that our proposed algorithm can provide the optimal SFC deployment solutions for requests and can guarantee the SFC trustworthiness at a controllable cost,thereby protecting SFCs from network attacks in complex security environments.
文摘Aspects of human behavior in cyber security allow more natural security to the user. This research focuses the appearance of anticipating cyber threats and their abstraction hierarchy levels on the mental picture levels of human. The study concerns the modeling of the behaviors of mental states of an individual under cyber attacks. The mental state of agents being not observable, we propose a non-stationary hidden Markov chain approach to model the agent mental behaviors. A renewal process based on a nonparametric estimation is also considered to investigate the spending time in a given mental state. In these approaches, the effects of the complexity of the cyber attacks are taken into account in the models.