A Hybrid Cyber Defense Mechanism to Mitigate the Persistent Scan and Foothold Attack

المؤلفون المشاركون

Liu, Xiaohu
Zhang, Yuchen
Wang, Shuo
Pei, Qingqi
Tang, Guangming

المصدر

Security and Communication Networks

العدد

المجلد 2020، العدد 2020 (31 ديسمبر/كانون الأول 2020)، ص ص. 1-15، 15ص.

الناشر

Hindawi Publishing Corporation

تاريخ النشر

2020-10-21

دولة النشر

مصر

عدد الصفحات

15

التخصصات الرئيسية

تكنولوجيا المعلومات وعلم الحاسوب

الملخص EN

As the prerequisite for the attacker to invade the target network, Persistent Scan and Foothold Attack (PSFA) is becoming progressively more subtle and complex.

Even worse, the static and predictable characteristics of traditional systems provide an asymmetric advantage for attackers in launching the PSFA.

To reverse this asymmetric advantage and resist the PSFA, two new defense ideas, called moving target defense (MTD) and deception-based cyber defense (DCD), have been suggested to provide the proactive selectable measures to complement traditional defense.

However, MTD is unable to defeat the sophisticated attacker with fingerprint tracking ability.

Meanwhile, DCD is easy to be marked by the attacker, which will result in a great waste of defense resources and poor defense effectiveness.

To address this shortcoming, we propose the hybrid cyber defense mechanism that combines the address mutation (belonging to MTD) and fingerprint camouflage (belonging to DCD) strategies.

More specifically, we first introduce and formalize the attacker model of PSFA based on the cyber kill chain.

Afterwards, the traffic direction technology is designed to realize the coordination between the strategy of address mutation and the strategy of fingerprint camouflage.

Furthermore, we construct the fine-grained quantitative modeling of the attacker’s behaviors through an in-depth observation of actual network confrontation.

Based on this, a dynamic defense strategy generation algorithm is presented to maximize the effectiveness of our hybrid mechanism.

Finally, the experimental results show that our hybrid mechanism can greatly improve the time required for a successful attack and achieve a better defense effect than the single strategy.

نمط استشهاد جمعية علماء النفس الأمريكية (APA)

Wang, Shuo& Pei, Qingqi& Zhang, Yuchen& Liu, Xiaohu& Tang, Guangming. 2020. A Hybrid Cyber Defense Mechanism to Mitigate the Persistent Scan and Foothold Attack. Security and Communication Networks،Vol. 2020, no. 2020, pp.1-15.
https://search.emarefa.net/detail/BIM-1208856

نمط استشهاد الجمعية الأمريكية للغات الحديثة (MLA)

Wang, Shuo…[et al.]. A Hybrid Cyber Defense Mechanism to Mitigate the Persistent Scan and Foothold Attack. Security and Communication Networks No. 2020 (2020), pp.1-15.
https://search.emarefa.net/detail/BIM-1208856

نمط استشهاد الجمعية الطبية الأمريكية (AMA)

Wang, Shuo& Pei, Qingqi& Zhang, Yuchen& Liu, Xiaohu& Tang, Guangming. A Hybrid Cyber Defense Mechanism to Mitigate the Persistent Scan and Foothold Attack. Security and Communication Networks. 2020. Vol. 2020, no. 2020, pp.1-15.
https://search.emarefa.net/detail/BIM-1208856

نوع البيانات

مقالات

لغة النص

الإنجليزية

الملاحظات

Includes bibliographical references

رقم السجل

BIM-1208856