期刊文献+

基于信息熵的分布式Web服务移动目标防御方案 被引量:1

Distributed Web Service Moving Target Defense Scheme Based on Information Entropy
下载PDF
导出
摘要 移动目标防御技术是为了改变传统静态防御的被动性所提出的一种主动防御技术,通过动态地变换系统中的各个攻击面来增加攻击者攻击的成本,实现主动防御。变换方式以及变换频率是移动目标防御系统的关键,目前移动目标防御系统的变换方式以及变换频率通常是管理者根据经验去设定,无法达到安全性和成本之间平衡的局面。针对这个问题,提出基于信息熵的分布式Web服务移动目标防御方案,方案通过信息熵的思想对异常流量进行识别和检测,进而根据检测结果来实时动态选取异构的变换模式以达到最大收益。进一步针对Web服务的防御策略进行研究设计。实验结果表明,该方案对网络状态识别和预测具有较高的准确性,并且多样化的变换策略能够有效抵御不同的攻击类型,增强了系统通信安全性及服务过程中的抗攻击能力。 The moving target defense technology is an active defense technology proposed to change the passiveness of the traditional static defense technology,which dynamically transforms each attack surface in the system to increase the cost of the attackers and achieve active defense.The transformation mode and the transformation frequency are key factors of the moving target defense system.At present,the transformation mode and transformation frequency of the moving target defense system are usually set manually by administrators according to their experience,and cannot achieve a balance between security and cost.Aiming at this problem,a distributed Web service moving target defense scheme based on information entropy is proposed.The scheme identifies and detects abnormal flow through information entropy theory,and then dynamically selects heterogeneous transform modes in real time according to the detection result to achieve maximum benefits.Then further research and design can be done according to the defense strategy of Web services.The experiment shows that the proposed scheme has high accuracy for network state recognition and prediction,and the diversified transformation strategy can effectively resist different kind of attacks,which enhances the system communication security and anti-attack capability in the service process.
作者 马猛飞 石乐义 魏东平 徐兴华 MA Meng-fei;SHI Le-yi;WEI Dong-ping;XU Xing-hua(School of Computer Science and Technology,China University of Petroleum(East China),Qingdao 266580,China;School of Oceanography and Space Informatics,China University of Petroleum(East China),Qingdao 266580,China)
出处 《计算机技术与发展》 2020年第10期131-136,共6页 Computer Technology and Development
基金 国家自然科学基金(61772551) 山东省自然科学基金(ZR201808160254)。
关键词 移动目标防御 分布式 信息熵 混沌序列 主动网络防御 moving target defense distributed information entropy chaotic sequence active network defense
  • 相关文献

参考文献6

二级参考文献36

  • 1高常波,罗万伯,王科.计算机网络安全系统设计[J].通信技术,2003,36(3):46-47. 被引量:4
  • 2李树军.基于协议转变的拒绝服务攻击技术的研究[J].计算机应用,2006,26(10):2323-2325. 被引量:4
  • 3LEE H, THING V. Port hopping for resilient networks[A]. Conf 60th IEEE Vehicular Technology[C]. 2004.3291-3295.
  • 4BADISHIY G. HERZBERG A, KEIDAR I, et al. Keeping denial-of-service attackers in the dark[A]. Int Symp Distributed Computing (DISC)[C]. Springer-Vedag, 2005.18-31.
  • 5SIFALAKIS M, SCHMID S, HUTCHISON D. Network address hopping: a mechanism to enhance data protection for packet communications[A]. ICC 2005[C]. 2005.1518 - 1523.
  • 6BBN Technologies. Applications that participate in their own defense[EB/OL].http://apod.bbn.com. 2002.
  • 7ATIGHETCHI M, PAL P, WEBBER E et al. Adaptive use of net- work-centric mechanisms in cyber-defense[A]. Proc 6th IEEE Int Syrup Object-Oriented Real-Tune Distributed Computing [C]. 2003. 183-192.
  • 8FERRARI L. The aglets-2.0.2 user's manual[EB/OL], http://aglets. sourceforge.net. 2004.
  • 9SUSHIL J, ANUP K G, VIPIN S, et. al. Moving Target Defense-Creating Asymmetric Uncertainty for Cyber Threats[M].[s.l.]:Springer Press, 2011:1.
  • 10NITRD CSIA IWG Cybersecurity Game-Change Research & Development Recommendations[R].U.S:NITRD, 2010.

共引文献244

同被引文献9

引证文献1

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部