Towards Deployment Strategies for Deception Systems

Towards Deployment Strategies for Deception Systems
复制标题

欺骗系统的部署策略

DOI:
--
复制
发表时间:
2017
期刊:
影响因子:
--
通讯作者:
Marc Zimmermann
Marc Zimmermann
中科院分区:
--
文献类型:
--
作者:
Daniel Fraunholz;Marc Zimmermann

文献摘要

被引文献

相似文献

网络安全通常建立在外围防御之上。复杂的攻击能够穿透边界并访问网络中的宝贵资源。更完整的防御策略还包含检测和缓解周边漏洞的机制。欺骗系统是一种很有前途的检测、欺骗和反渗透技术。在这项工作中,我们提供了基于欺骗的网络防御的基本机制的见解,并详细讨论了该技术最重要的缺点之一:部署。我们还提出了一个解决方案,使欺骗系统,以广泛的用户。这是通过基于机器学习的动态部署策略来实现的,以适应网络环境。不同的方法,算法和组合进行评估,最终建立一个完整的自适应部署框架。建议的框架需要最少的配置和维护。
Network security is often built on perimeter defense. Sophisticated attacks are able to penetrate the perimeter and access valuable resources in the network. A more complete defense strategy also contains mechanisms to detect and mitigate perimeter breaches. Deceptive systems are a promising technology to detect, deceive and counter infiltrations. In this work we provide an insight in the basic mechanisms of deception based cyber defense and discuss in detail one of the most significant drawbacks of the technology: The deployment. We also propose a solution to enable deception systems to a broad range of users. This is achieved by a dynamic deployment strategy based on machine learning to adapt to the network context. Di ff erent methods, algorithms and combinations are evaluated to eventually build a full adaptive deployment framework. The proposed framework needs a minimal amount of configuration and maintenance.