Quantifying Cybersecurity Effectiveness of Dynamic Network Diversity

Quantifying Cybersecurity Effectiveness of Dynamic Network Diversity
复制标题

DOI:
10.1109/tdsc.2021.3107514
复制
发表时间:
2021-08
影响因子:
7.3
通讯作者:
Huashan Chen;H. Çam;Shouhuai Xu
Huashan Chen;H. Çam;Shouhuai Xu
中科院分区:
计算机科学2区
文献类型:
--
作者:
Huashan Chen;H. Çam;Shouhuai Xu

文献摘要

相似文献

部署单一文化的软件栈可能会产生毁灭性的后果,因为一次攻击就可能危及网络空间中所有易受攻击的计算机。这种“一个漏洞影响所有人”的现象将持续到软件栈多样化之后,这一点已被研究界所公认。然而,现有的研究主要集中在调查软件多样性在构建块级别的有效性(例如,两个独立的实现是否确实表现出独立的脆弱性);实施网络范围的软件多样性的有效性很少被理解,尽管其在可能帮助证明软件多样化投资的合理性方面的重要性。作为最终解决这一问题的第一步,我们提出了一个系统的框架,用于建模和量化网络多样性的网络安全有效性,包括一套网络安全指标。我们还提出了一个基于代理的模拟来实证证明该框架的有用性。我们得出了一些见解,包括令人惊讶的结果,即主动多样性在非常特殊的情况下是有效的,但反应适应多样性在大多数情况下更有效。
The deployment of monoculture software stacks can have devastating consequences because a single attack can compromise all of the vulnerable computers in cyberspace. This one-vulnerability-affects-all phenomenon will continue until after software stacks are diversified, which is well recognized by the research community. However, existing studies mainly focused on investigating the effectiveness of software diversity at the building-block level (e.g., whether two independent implementations indeed exhibit independent vulnerabilities); the effectiveness of enforcing network-wide software diversity is little understood, despite its importance in possibly helping justify investment in software diversification. As a first step towards ultimately tackling this problem, we propose a systematic framework for modeling and quantifying the cybersecurity effectiveness of network diversity, including a suite of cybersecurity metrics. We also present an agent-based simulation to empirically demonstrate the usefulness of the framework. We draw a number of insights, including the surprising result that proactive diversity is effective under very special circumstances, but reactive-adaptive diversity is much more effective in most cases.