课题基金 / 基金详情

针对工业网络高可用性的主动安全防御机理研究

批准号:
62102375
项目类别:
青年科学基金项目(C类)
资助金额:
30.0 万元
负责人:
周伯阳
依托单位:
学科分类:
网络与系统安全
结题年份:
2024
批准年份:
2021
项目状态:
已结题
项目参与者:
周伯阳

项目摘要

结项摘要

相似基金

相关文献

中文摘要
随着智能化的发展,现代工业网络的可用性面临着链路泛洪攻击(LFA)、网络拥塞或故障破坏等新的威胁,可造成状态测量与估计错误和控制勿动,其自身的安全保障存在如下不足:1)复杂隐蔽LFA防御方法存在攻击目标易被获取、关键路由难被迂回、攻击源检测成本极大等瓶颈问题;2)端到端丢包重传效率低,且网络结构冗余性利用不充分,难以满足强实时性要求。为此,本项目研究针对工业网络高可用性的主动安全防御机理,包括:1)复杂隐蔽LFA高效防御机制,检测被攻击的关键路由及其主机等意图,为其创建多功能等价的随机化变体以大幅度增加多样性,使攻击前置条件难成立,提升防御效果;2)弹性鲁棒通信协议,构建涵盖网络节点间多冗余子路径的可靠性最优交叠路由,满足端到端通信延迟要求,并利用工业数据流式特性,实现逐跳快速检测丢包,以及多子路径的短时高效重传,最大化端到端所容许的丢包率。上述工作将极大提升工业网络可用性的安全保障能力。
英文摘要
With intelligence development, the availability of the modern industrial networks faces a set of new security threats including link flooding attacks (LFAs), as well as network congestion or failures and disruptions that can lead to state measurement and estimation errors as well as wrong controls. The security assurance of the networks themselves has following deficiencies: (i) There are some bottleneck issues in the defense methods for the complicated and stealthy LFAs including the easiness in acquisition of the attacking objectives, the harness in detouring for critical routes, as well as the high cost in detection of the attacking sources. (ii) The end-to-end retransmissions for lost packets are at low efficiency, and the exploitation in the network structural redundancy is insufficient, which are hard to meet the rigid real timeliness demand in the communication. To this end, the project researches on the proactive security defense mechanism for the high availability of industrial networks that includes following content: (a) The efficient proactive defense mechanism for the complicated and stealthy LFA firstly detects the attacking intentions including the persistent routes and their hosts. Then, it creates the multiple functional equivalent randomized variants for them to significantly increase their diversity. Thus, the attacking precondition is hard to be established, which improves the defense effectiveness. (b) The resilient and robust communication protocol constructs the non-disjoint routes in optimal reliability that involve the multiple redundant sub-paths between network nodes. Further, the routes meet the rigid real-time communication demand. In addition, by exploiting the streaming features in the measurement data, the protocol achieves the lost packet detection in a hop-by-hop manner, as well as the efficient retransmission control in a short time, which maximizes the tolerable loss rate in the end-to-end communication. The above work will significantly improve the security assurance capability for the availability of the industrial networks.
随着智能化的发展,云端化的现代工业网络面临双重可用性威胁:一是隐蔽链路泛洪攻击(LFA),通过泛洪造成持久路由(PR)拥塞,这类PR易被攻击者探测和利用。二是复杂数据传输故障,现有的重传控制和快速重路由机制在主转发路径的子路径利用方面存在不足,难以应对多链路故障,可靠性较低;此外,云应用在数据中心网络(DCN)中难以精准选择多跳路径避开链路故障。这些问题可能导致工业设施状态估计错误,威胁其安全稳定运行。.为此,本项目研究了面向工业网络高可用性的主动安全防御机制,提出以下创新成果:.1. 高效PR多样化防御机制(PRDD):针对LFA攻击,设计了检测攻击意图、生成并下发多代理防御策略的机制,使攻击者难以侦测受害PR。针对再次被攻击的PR,通过流量控制防止网络拥塞。结合深度神经网络和随机森林技术,提高攻击意图识别的准确性,从而增强防御能力。.2. 弹性鲁棒数据通信协议(DRTP):提出基于子路径路由的逐跳重传控制与数据转发机制,实现低丢包率和低延迟的强实时性通信,并给出DRTP的高效实现方案(RSDD)。通过最小化重传失败率,优化可靠子路径生成算法,提升协议性能;提出流量感知的快速主动重路由技术,利用子路径降低重路由失败率,实现多故障条件下的高效恢复。同时,设计了DCN路径选择器(HPS),通过多比特数据包头部修改,使源主机能够精准选择多跳路径,避开链路故障。.3.工业网络高可用性防御原型及验证:构建了典型智能电网测试场景,验证所提技术的性能优势。结果表明,PRDD能够精准识别攻击意图,全面保护受害PR,显著降低网络拥塞风险。DRTP及其RSDD在严重链路破坏下实现业内最低数据丢包率,并降低多达29.11%,同时显著降低延迟,确保电网状态估计准确可见;重路由机制高效应对多链路故障,生产网络故障恢复时间达领先的0.4至98.9ms;HPS路径选择准确率高达95.9%,显著提升了路径选择可靠性。.本项目上述研究成果为工业网络在复杂威胁下提供了强有力的高可用性保障,在关键性领域展现出显著应用价值。
国内基金
海外基金