|国家预印本平台
首页|一种防范物隔攻击的拟态防御模型

一种防范物隔攻击的拟态防御模型

Model of Mimic Defense againsting Air-gap Attacks

中文摘要英文摘要

物隔攻击与拟态防御存在于当前网络攻与防两个针锋相对领域的两大新兴技术。然而,华山论剑尚未及在现实世界中出现,是攻方技高一筹,还是守方棋高一着?为此,结合双方核心技术原理对可能的博弈空间进行初步分析。在此基础上,给出一种在拟态防御设备上部署物隔攻击检测器的架构模型。首先,动态异构冗余结构被用于防范物隔攻击恶意软件;其次,物隔攻击检测算法(检测器)被用于检测物隔攻击发送器发送的信号;最后,把动态异构冗余结构与物隔攻击检测器用某种逻辑组织起来,就获得了所提架构模型。仿真实验结果初步证实了新模型的能力。

ir-gap attacks and mimic defense are two emerging techniques in the field of network attack and defense, respectively. However, direct confrontation between them has not yet appeared in the real world. Who will be the winner, if air-gap attacks encounter mimic defense? To this end, a preliminary analysis is conducted for exploring the possible the strategy space of game according to the core principles of air-gap attacks and mimic defense. On this basis, an architecture model is proposed, which combines some detectors for air-gap attacks and mimic defense devices. First, a dynamic heterogeneous redundancy structure is employed to be on guard against malicious software of air-gap attacks. Second, some detectors for air-gap attacks are used to detect some signal sent by air-gap attackers\' transmitter. Third, the proposed architecture model is obtained by organizing the dynamic heterogenIf Air-Gap Attacks Encounter Mimic Defenseeous redundancy structure and detectors for air-gap attacks with some logical relationship. The simulated experimental results preliminarily confirm the ability of the new model.

朱维军

电子对抗

网络安全物隔攻击拟态防御动态异构冗余入侵检测

network securityair-gap attacksmimic defensedynamic heterogeneous redundancyintrusion detection

朱维军.一种防范物隔攻击的拟态防御模型[EB/OL].(2019-03-15)[2025-08-19].http://www.paper.edu.cn/releasepaper/content/201903-186.点此复制

评论