首页 | 本学科首页   官方微博 | 高级检索  
     

基于动态异构冗余机制的路由器拟态防御体系结构
作者姓名:马海龙  伊鹏  江逸茗  贺磊
作者单位:解放军信息工程大学信息技术研究所 郑州 中国 450000,解放军信息工程大学信息技术研究所 郑州 中国 450000,解放军信息工程大学信息技术研究所 郑州 中国 450000,解放军信息工程大学信息技术研究所 郑州 中国 450000
基金项目:本课题得到国家重点研发计划(2016YFB0800103)资助。
摘    要:路由器作为网络空间的基础核心要素,其安全性能对网络安全具有决定性意义。但由于它的封闭性、专用性和复杂性,导致其存在的漏洞更多,后门隐藏更深。目前对路由器的安全防御手段均为被动式“补漏洞、堵后门”的“亡羊补牢”式的防御,不仅防御滞后更无法应对未知的安全威胁。本文基于拟态防御技术,在路由器体系架构上引入异构冗余功能执行体,通过动态调度机制,随机选择多个异构执行体工作,在相同外部激励的情况下,通过比对多个异构功能执行体的输出结果,对功能执行体进行异常检测,实现路由系统的主动防御。实验结果表明,该架构可以明显提升攻击链中每一步攻击的实施难度,增加攻击成本,并能抵御基于未知漏洞与后门的攻击。

关 键 词:拟态防御  动态  异构  冗余  路由器
收稿时间:2016/9/12 0:00:00
修稿时间:2016/10/9 0:00:00

Dynamic Heterogeneous Redundancy based Router Architecture with Mimic Defenses
Authors:MA Hailong  YI Peng  JIANG Yiming and HE Lei
Affiliation:Institute of Information Technology, PLA Information Engineering University, Zhengzhou 450000, China,Institute of Information Technology, PLA Information Engineering University, Zhengzhou 450000, China,Institute of Information Technology, PLA Information Engineering University, Zhengzhou 450000, China and Institute of Information Technology, PLA Information Engineering University, Zhengzhou 450000, China
Abstract:As a fundamental core element of cyberspace, the security performance of router plays a decisive significance in network security. However, the closeness, specificity and complexity of router lead to more loopholes and make backdoors hidden deeper. Currently, defense means of router are passive, which is "mend the fold after the sheep have been stolen"-like. Such defense means is not only hysteretic but also helpless against unknown security threats. Based on mimicry defense technology, heterogeneous redundancy function entities are introduces to the architecture of router. With dynamic scheduling mechanism, multiple heterogeneous execution entities are randomly selected to work. Under the same external motivations, by comparing the output of heterogeneous executing entities and conducting anomaly detection on heterogeneous executing entities, the routing system could perform active defense. Experimental results show that this architecture can significantly increase the attack difficulty in every step of the attack chain, increase the cost of attacks, and can withstand attacks based on unknown vulnerabilities and backdoors.
Keywords:Mimic defense  Dynamic  Heterogeneous  Redundancy  Router
点击此处可从《》浏览原始摘要信息
点击此处可从《》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号