Deceiving Network Reconnaissance Using SDN-Based Virtual Topologies

Deceiving Network Reconnaissance Using SDN-Based Virtual Topologies
复制标题

DOI:
10.1109/tnsm.2017.2724239
复制
发表时间:
2017-12-01
影响因子:
5.3
通讯作者:
Chadha, Ritu
Chadha, Ritu
中科院分区:
计算机科学2区
文献类型:
--
作者:
Achleitner, Stefan;La Porta, Thomas F.;Chadha, Ritu

文献摘要

被引文献

相似文献

先进的有针对性的网络攻击通常依赖于侦察任务来收集有关潜在目标、其特征和位置的信息,以识别网络环境中的漏洞。高级网络扫描技术通常用于此目的,并由受恶意软件感染的主机自动执行。本文对网络欺骗进行了形式化的定义,并提出了一种基于软件定义网络的网络欺骗系统,通过模拟虚拟拓扑结构来实现网络欺骗。我们的系统通过延迟对手的扫描技术并使其收集的信息无效来阻止网络侦察,同时限制对良性网络流量的性能影响。通过模拟网络的拓扑和物理特征,我们引入了一个系统,该系统用虚拟信息欺骗恶意网络发现和侦察技术,同时限制攻击者能够从真实底层系统获取的信息。这种方法展示了一种针对敌对侦察任务的新型防御技术,这些任务是有针对性的网络攻击所必需的,例如高度连接环境中的高级持续威胁。我们的系统的防御步骤旨在使攻击者的信息无效,延迟发现脆弱主机的过程,并识别网络中的对抗性侦察的来源。
Advanced targeted cyber attacks often rely on reconnaissance missions to gather information about potential targets, their characteristics and location to identify vulnerabilities in a networked environment. Advanced network scanning techniques are often used for this purpose and are automatically executed by malware infected hosts. In this paper, we formally define network deception to defend reconnaissance and develop a reconnaissance deception system, which is based on software defined networking, to achieve deception by simulating virtual topologies. Our system thwarts network reconnaissance by delaying the scanning techniques of adversaries and invalidating their collected information, while limiting the performance impact on benign network traffic. By simulating the topological as well as physical characteristics of networks, we introduce a system which deceives malicious network discovery and reconnaissance techniques with virtual information, while limiting the information an attacker is able to harvest from the true underlying system. This approach shows a novel defense technique against adversarial reconnaissance missions which are required for targeted cyber attacks such as advanced persistent threats in highly connected environments. The defense steps of our system aim to invalidate an attackers information, delay the process of finding vulnerable hosts and identify the source of adversarial reconnaissance within a network.