NetProtect: Network Perturbations to Protect Nodes against Entry-Point Attack

NetProtect: Network Perturbations to Protect Nodes against Entry-Point Attack
复制标题

NetProtect:通过网络扰动保护节点免受入口点攻击

DOI:
10.1145/3447535.3462500
复制
发表时间:
2021
期刊:
ACM Web Science Conference
影响因子:
--
通讯作者:
Soundarajan, Sucheta
Soundarajan, Sucheta
中科院分区:
--
文献类型:
--
作者:
Laishram, Ricky;Hozhabrierdi, Pegah;Wendt, Jeremy;Soundarajan, Sucheta

文献摘要

参考文献

相似文献

在许多网络应用程序中,可能需要隐藏某些目标节点,使其不被数据收集器检测到,数据收集器使用爬行算法来探索网络。例如,在计算机网络中,网络管理员可能希望保护那些包含敏感信息的计算机(目标节点),使其不被利用易受攻击的机器进入网络的黑客发现。这些网络通常通过隐藏机器(节点)来防止外部访问,并且只允许固定的入口点进入系统(防止外部攻击)。然而,在这种保护方案中,一旦一个入口点被攻破,所有内部机器的安全就会受到威胁(即外部攻击变成内部攻击)。在本文中,我们从数据保护的角度来看待这个问题。我们提出了节点保护问题:给定一个已知入口点的网络,为了保护尽可能多的目标节点免受数据收集器的攻击,应该删除/添加哪些边?解决这个问题的一个简单方法是简单地断开入口点或目标节点,但这会使网络无法正常工作。因此,我们施加了一定的约束:对于每个节点,只有(1−r)部分的边可以被移除,并且得到的网络不能断开。我们提出了两种新的评分机制-频繁路径评分和最短路径评分。利用这些分数,我们提出了NetProtect算法,该算法选择要删除或添加的边,以最好地阻止数据收集器的进度。我们通过实验证明,NetProtect在多个真实网络中优于基线节点保护算法。在一些数据集中,使用NetProtect删除1%的边缘,我们发现数据收集器需要高达6(4)倍的预算,以发现5(50)个节点。
In many network applications, it may be desirable to conceal certain target nodes from detection by a data collector, who is using a crawling algorithm to explore a network. For example, in a computer network, the network administrator may wish to protect those computers (target nodes) with sensitive information from discovery by a hacker who has exploited vulnerable machines and entered the network. These networks are often protected by hiding the machines (nodes) from external access, and allow only fixed entry points into the system (protection against external attacks). However, in this protection scheme, once one of the entry points is breached, the safety of all internal machines is jeopardized (i.e., the external attack turns into an internal attack). In this paper, we view this problem from the perspective of the data protector. We propose the Node Protection Problem: given a network with known entry points, which edges should be removed/added so as to protect as many target nodes from the data collector as possible? A trivial way to solve this problem would be to simply disconnect either the entry points or the target nodes – but that would make the network non-functional. Accordingly, we impose certain constraints: for each node, only (1 − r) fraction of its edges can be removed, and the resulting network must not be disconnected. We propose two novel scoring mechanisms - the Frequent Path Score and the Shortest Path Score. Using these scores, we propose NetProtect, an algorithm that selects edges to be removed or added so as to best impede the progress of the data collector. We show experimentally that NetProtect outperforms baseline node protection algorithms across several real-world networks. In some datasets, With 1% of the edges removed by NetProtect, we found that the data collector requires up to 6 (4) times the budget compared to the next best baseline in order to discover 5 (50) nodes.
第四届网络安全和信息情报研究年度研讨会 - 制定应对未来网络安全和信息情报挑战的策略,CSIIRW 08,美国田纳西州橡树岭,2008 年 5 月 12-14 日
DOI: 10.1145/1413140
发表时间: 2008
影响因子: 2.2
作者:
Frederick T. Sheldon;A. Krings;R. Abercrombie;A. Mili
通讯作者: A. Mili
跳箱服务器是否应该成为历史?
DOI: 10.1016/s1353-4858(17)30092-2
发表时间: 2017
期刊: Netw. Secur.
影响因子: --
作者:
C. Steffen
通讯作者: C. Steffen
最好的 Windows Server 2008 图书时期
DOI: 10.1016/b978-1-59749-273-7.x0001-8
发表时间: 2008
期刊: Wiley Interdisciplinary Reviews: Data Mining and Knowledge Discovery
影响因子: --
作者:
Anthony Piltzecker
通讯作者: Anthony Piltzecker