An active defense model based on situational awareness and firewalls

被引:2
|
作者
Li, Di [1 ,2 ]
Hu, Yikun [1 ,3 ]
Xiao, Guoqing [1 ,3 ]
Duan, Mingxing [1 ]
Li, Kenli [1 ]
机构
[1] Hunan Univ, Coll Comp Sci & Elect Engn, Changsha, Hunan, Peoples R China
[2] Hunan Agr Univ, Informat & Network Ctr, Changsha, Hunan, Peoples R China
[3] Hunan Univ, Coll Comp Sci & Elect Engn, Changsha 410082, Hunan, Peoples R China
来源
基金
中国国家自然科学基金; 国家重点研发计划;
关键词
active defense; cyber attack and defense; defense cost; game theory; SECURITY;
D O I
10.1002/cpe.7577
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
With the rapid development of the internet, cyberspace security issues have become increasingly prominent. The importance of constructing a cyberspace security system is self-evident, but compared with attackers, defenders in cyberspace are in a castle-like passive defense state in most cases. Therefore, building a reliable, accurate, timely, and active defense system is challenging. The key is to accurately focus on defense priorities, the anticipation of attackers who will likely succeed, and blocking attacks in a timely manner. In this article, we propose an active defense model based on the interaction of situational awareness and firewalls. First, by biasing the integrity, confidentiality, and availability of assets to get the score of assets, and using the Common Vulnerability Scoring System to assess the threat level of assets, we combine the two to determine the maximum system damage that the asset will suffer if it is lost, and then focus on defense. Meanwhile, log analysis of the network situational awareness platform can predict successful attackers, and then the linked firewall strategy can block these attacks in time before the attackers obtain attack gains. After that, we force the attackers to give up their attacks on the target by increasing the attack cost. We compared our model with iptables auto-blocking and nginx auto-blocking, and our model excelled them across the board in terms of comprehensiveness and false positive rate. The experimental results verify thar our active defense model proposed in this article can better reduce the defense cost and increase the attack cost, thus achieving the relatively defense goal.
引用
收藏
页数:18
相关论文
共 50 条
  • [1] Towards a Theoretical Framework for an Active Cyber Situational Awareness Model
    Al-Shamisi, Ahmed
    Louvieris, Panos
    Al-Mualla, Mohammed
    Mihajlov, Martin
    [J]. PROCEEDINGS OF THE 23RD INTERNATIONAL CONFERENCE ON SYSTEMS, SIGNALS AND IMAGE PROCESSING, (IWSSIP 2016), 2016, : 263 - 268
  • [2] Automated situational awareness sensing for homeland defense
    Reichard, KM
    Crow, EC
    Swanson, DC
    [J]. SYSTEM DIAGNOSIS AND PROGNOSIS: SECURITY AND CONDITION MONITORING ISSUES III, 2003, 5107 : 64 - 71
  • [3] Firewalls: An outdated defense
    Arbaugh, WA
    [J]. COMPUTER, 2003, 36 (06) : 112 - 113
  • [4] Network security situational awareness model based on threat intelligence
    Zhang, Hongbin
    Yin, Yan
    Zhao, Dongmei
    Liu, Bin
    [J]. Tongxin Xuebao/Journal on Communications, 2021, 42 (06): : 182 - 194
  • [5] A Network Security Situational Awareness Model Based on Information Fusion
    Abasi
    [J]. ADVANCES IN MECHATRONICS, AUTOMATION AND APPLIED INFORMATION TECHNOLOGIES, PTS 1 AND 2, 2014, 846-847 : 1632 - 1635
  • [6] The Role of Situational Awareness in Cyber Security and Cyber Defense Strategy
    Onwubiko, Cyril
    [J]. 2015 International Conference on Cyber Situational Awareness, Data Analytics and Assessment (CyberSA), 2015,
  • [7] Analysis Model of Situational Awareness in Flight
    Jiang, Yong-Zhou
    Xu, Tao
    [J]. 2016 INTERNATIONAL CONFERENCE ON ENERGY DEVELOPMENT AND ENVIRONMENTAL PROTECTION (EDEP 2016), 2016, : 511 - 515
  • [8] A Computational Model of Cyber Situational Awareness
    Dobson, Geoffrey B.
    Carley, Kathleen M.
    [J]. SOCIAL, CULTURAL, AND BEHAVIORAL MODELING, SBP-BRIMS 2018, 2018, 10899 : 395 - 400
  • [9] A Cloud Security Situational Awareness Model based on Parallel Apriori Algorithm
    Liang Xiao
    Lv Hongwu
    Guo Fangfang
    Wang Huiqiang
    [J]. MECHATRONICS ENGINEERING, COMPUTING AND INFORMATION TECHNOLOGY, 2014, 556-562 : 6294 - 6297
  • [10] A Decision-support Model for Information Systems Based on Situational Awareness
    Hu He
    Wang Xiaojing
    Yang Xin
    [J]. MINES 2009: FIRST INTERNATIONAL CONFERENCE ON MULTIMEDIA INFORMATION NETWORKING AND SECURITY, VOL 2, PROCEEDINGS, 2009, : 405 - +