首页 | 官方网站   微博 | 高级检索  
     

一种基于多阶段攻击响应的SDN动态蜜罐
引用本文:王鹃,杨泓远,樊成阳. 一种基于多阶段攻击响应的SDN动态蜜罐[J]. 信息网络安全, 2021, 0(1): 27-40
作者姓名:王鹃  杨泓远  樊成阳
作者单位:武汉大学国家网络安全学院;空天信息安全与可信计算教育部重点实验室
基金项目:国家自然科学基金[61872430]。
摘    要:蜜罐作为一种主动防御机制,可以通过部署诱饵目标,主动吸引攻击者与虚假资源进行交互,从而在防止有价值的真实资源受到破坏的同时,也能根据收集到的数据分析攻击行为并主动应对.然而,现有蜜罐方案存在无法针对复杂攻击手段部署特定蜜罐防御;蜜罐攻防博弈中动态性考虑不够充分,无法根据收益与成本有效选择蜜罐最佳防御策略;以及性能开销较...

关 键 词:蜜罐  攻击图  不完全信息动态博弈  软件定义网络  Docker

A SDN Dynamic Honeypot with Multi-phase Attack Response
WANG Juan,YANG Hongyuan,FAN Chengyang. A SDN Dynamic Honeypot with Multi-phase Attack Response[J]. Netinfo Security, 2021, 0(1): 27-40
Authors:WANG Juan  YANG Hongyuan  FAN Chengyang
Affiliation:(School of Cyber Science and Engineering,Wuhan University,Wuhan 430072,China;Key Laboratory of Aerospace Information Security and Trusted Computing,Ministry of Education,Wuhan 430072,China)
Abstract:As an active defense mechanism,a honeypot can actively attract attackers to interact with imitative and illusive resources by deploying decoy targets,which can not only prevent valuable real assets from being destroyed,but also analyze and deal with the attack behaviors according to the collected data.However,the existing honeypot systems have some limitations,such as unable to deploy specific defense honeypots for complex attack scenarios,unable to select the best defense strategy according to the benefits and costs because of the insufficient dynamic consideration in honeypot attack and defense game,and the performance overhead is large.This paper proposes a SDN dynamic honeypot architecture based on multiphase attack response and dynamic game theory,presents a deployment strategy for SDN dynamic honeypot by using Docker,and implements a novel dynamic honeypot system which can be dynamically adjusted according the different attack phases.Experiments show that the system can quickly and dynamically generate a targeted honeypot for response according to the network situation and the behaviors of attackers,which effectively improves the dynamic and deception ability of honeypot.
Keywords:Honeypot  attack graph  game of dynamic incomplete information  software defined network  Docker
本文献已被 维普 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司    京ICP备09084417号-23

京公网安备 11010802026262号