An active defense model based on situational awareness and firewalls

被引:2
|
作者
Li, Di [1 ,2 ]
Hu, Yikun [1 ,3 ]
Xiao, Guoqing [1 ,3 ]
Duan, Mingxing [1 ]
Li, Kenli [1 ]
机构
[1] Hunan Univ, Coll Comp Sci & Elect Engn, Changsha, Hunan, Peoples R China
[2] Hunan Agr Univ, Informat & Network Ctr, Changsha, Hunan, Peoples R China
[3] Hunan Univ, Coll Comp Sci & Elect Engn, Changsha 410082, Hunan, Peoples R China
来源
基金
中国国家自然科学基金; 国家重点研发计划;
关键词
active defense; cyber attack and defense; defense cost; game theory; SECURITY;
D O I
10.1002/cpe.7577
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
With the rapid development of the internet, cyberspace security issues have become increasingly prominent. The importance of constructing a cyberspace security system is self-evident, but compared with attackers, defenders in cyberspace are in a castle-like passive defense state in most cases. Therefore, building a reliable, accurate, timely, and active defense system is challenging. The key is to accurately focus on defense priorities, the anticipation of attackers who will likely succeed, and blocking attacks in a timely manner. In this article, we propose an active defense model based on the interaction of situational awareness and firewalls. First, by biasing the integrity, confidentiality, and availability of assets to get the score of assets, and using the Common Vulnerability Scoring System to assess the threat level of assets, we combine the two to determine the maximum system damage that the asset will suffer if it is lost, and then focus on defense. Meanwhile, log analysis of the network situational awareness platform can predict successful attackers, and then the linked firewall strategy can block these attacks in time before the attackers obtain attack gains. After that, we force the attackers to give up their attacks on the target by increasing the attack cost. We compared our model with iptables auto-blocking and nginx auto-blocking, and our model excelled them across the board in terms of comprehensiveness and false positive rate. The experimental results verify thar our active defense model proposed in this article can better reduce the defense cost and increase the attack cost, thus achieving the relatively defense goal.
引用
收藏
页数:18
相关论文
共 50 条
  • [31] Situational Awareness based Flight Control of a Drone
    Astrov, Igor
    Pedai, Andrus
    [J]. 2011 IEEE INTERNATIONAL SYSTEMS CONFERENCE (SYSCON 2011), 2011, : 574 - 578
  • [32] Design of Situational Awareness System Based on ARM
    Nian, Yangji
    Na, Chengli
    Fei, Liusheng
    Lin, Sunqing
    [J]. 2015 INTERNATIONAL CONFERENCE ON INFORMATION SCIENCE AND INTELLIGENT CONTROL (ISIC 2015), 2015, : 247 - 252
  • [33] Blockchain Security Situational Awareness Method Based on
    Luo, Zhiyong
    Song, Weiwei
    Zhang, Wenbo
    Wang, Jianming
    Li, Jie
    [J]. JOURNAL OF ELECTRONICS & INFORMATION TECHNOLOGY, 2023, 45 (04) : 1374 - 1382
  • [34] NEOSSAT: MICROSATELLITE BASED SPACE SITUATIONAL AWARENESS
    Thorsteinson, Stefan
    Scott, Robert
    Wallace, Brad
    [J]. GUIDANCE, NAVIGATION, AND CONTROL 2015, 2015, 154 : 479 - 489
  • [35] A Graph Model for Enhancing Situational Awareness in Power Systems
    Gavgani, Mirjavad Hashemi
    Eftekharnejad, Sara
    [J]. 2017 19TH INTERNATIONAL CONFERENCE ON INTELLIGENT SYSTEM APPLICATION TO POWER SYSTEMS (ISAP), 2017,
  • [36] A NEW DYNAMIC DEFENSE MODEL BASED ON ACTIVE DECEPTION
    Gong Jing Sun Zhixin Gu Qiang(College of Mathematics & Physics
    [J]. Journal of Electronics(China), 2009, 26 (02) : 205 - 213
  • [37] Using Augmented Virtuality to Understand the Situational Awareness Model
    Bhandari, Siddharth
    Hallowell, Matthew R.
    van Boven, Leaf
    Golparvar-Fard, Mani
    Gruber, June
    Welker, Keith M.
    [J]. CONSTRUCTION RESEARCH CONGRESS 2018: SAFETY AND DISASTER MANAGEMENT, 2018, : 105 - 115
  • [38] Algebraic Model for Knowledge Representation in Situational Awareness Systems
    Mykich, Khrystyna
    Burov, Yevhen
    [J]. 2016 XITH INTERNATIONAL SCIENTIFIC AND TECHNICAL CONFERENCE COMPUTER SCIENCES AND INFORMATION TECHNOLOGIES (CSIT), 2016, : 165 - 167
  • [39] Network security model based on active defense and passive defense hybrid strategy
    Zhao, Gaoli
    Song, Junping
    [J]. JOURNAL OF INTELLIGENT & FUZZY SYSTEMS, 2020, 39 (06) : 8897 - 8905
  • [40] A Document-based Data Model for Large Scale Computational Maritime Situational Awareness
    Cazzanti, Luca
    Millefiori, Leonardo M.
    Arcieri, Gianfranco
    [J]. PROCEEDINGS 2015 IEEE INTERNATIONAL CONFERENCE ON BIG DATA, 2015, : 1350 - 1356