Detection and Isolation Malware by Dynamic Routing Moving Target Defense with Proxies

Detection and Isolation Malware by Dynamic Routing Moving Target Defense with Proxies
复制标题

DOI:
10.1109/csci58124.2022.00189
复制
发表时间:
2022-12
期刊:
2022 International Conference on Computational Science and Computational Intelligence (CSCI)
影响因子:
--
通讯作者:
Kouki Inoue;Hiroshi Koide
Kouki Inoue;Hiroshi Koide
中科院分区:
其他
文献类型:
--
作者:
Kouki Inoue;Hiroshi Koide

文献摘要

相似文献

近年来,许多公司和组织都引入了内部网络,而这种内部网络提议的可用性和便利性,在许多情况下,恶意局外人侵犯了这些本地网络,并通过网络攻击泄露了客户信息最近有一种称为“高级持续威胁”的攻击(与传统的网络攻击不同,这些攻击都针对特定的目标。不会立即攻击目标,而是要长时间调查系统并收集移动目标防御,这是一项动态改变网络攻击目标的系统的技术。基于代理的网络级MTD在内部网络中检测和隔离恶意软件。
In recent years, many companies and organizations have introduced internal networks. While such internal networks propose availability and convenience, there have been many cases in which malicious outsiders have intruded on these local networks, and leaked customer information through cyber attacks. In addition, there have recently been reports of a type of attack called “Advanced Persistent Threats (APT)”. Unlike conventional cyber attacks, these attacks target specific objectives. And they use sophisticated techniques to penetrate the target's system. Once malware successes to intrude into the system, malware does not immediately attack the target but hides for a long time to investigate the system and gather information. Moving Target Defense, MTD is a technology that dynamically changes the configurations of systems targeted by cyber attacks. In this study, we implemented a model using a proxy-based network-level MTD to detect and quarantine malware in internal networks. And we can confirm that the proposed method is effective in the detection and quarantine of malware.