ZHENG Qiu-hua,HU Cheng-nan,CUI Ting-ting,et al.A Security Analysis Approach for Dynamic Heterogeneous Redundancy Model Based on Probability Analysis[J].ACTA ELECTRONICA SINICA,2021,49(08):1586-1598.
ZHENG Qiu-hua,HU Cheng-nan,CUI Ting-ting,et al.A Security Analysis Approach for Dynamic Heterogeneous Redundancy Model Based on Probability Analysis[J].ACTA ELECTRONICA SINICA,2021,49(08):1586-1598. DOI: 10.12263/DZXB.20201063.
A Security Analysis Approach for Dynamic Heterogeneous Redundancy Model Based on Probability Analysis
The security analysis of the dynamic heterogeneous redundancy (DHR) system is one key issue of the cyber mimic defense. We propose the executor-vulnerability matrix (MEV) and the servant-vulnerability matrix (MSV) to achieve the formal representation of the DHR system. On this basis
the attack sequence method and the servant method are proposed to analyze DHR systems’ security from the attack success rate and controlled time rate. we deduce the security index calculation under (non-)collusion blind attack and (non-)collusion optimal attack scenarios. Therefore
we analyze the influence of various factors on DHR security through simulation experiments. We give several suggestions to enhance the DHR system’s security. The proposed approach can be used to analyze DHR systems’ security and assist in constructing DHR systems.
关键词
Keywords
references
White House . Trustworthy cyberspace: strategic plan for the federal cyber security research and development program [R]. Report of the National Science and Technology Council, Executive Office of the President , 2011 .
Wang Z P , Hu H C , Cheng G Z . A DNS architecture based on mimic security defense [J]. Acta Electronica Sinica , 2017 , 45 ( 11 ): 2705 - 2714 . (in Chinese)
Wang W , Zeng J J , Li G S , et al . Security analysis of dynamic heterogeneous redundant system [J]. Computer Engineering , 2018 , 44 ( 10 ): 42 - 45, 50 . (in Chinese)
Guo W , Wu J X , Zhang F , et al . A cyberspace attack and defense model with security performance analysis based on automata theory [J]. Journal of Cyber Security , 2016 , 1 ( 4 ): 29 - 39 . (in Chinese)
Zhu W J , Guo Y B , Huang B H . A mimic defense automaton model of dynamic heterogeneous redundancy structures [J]. Acta Electronica Sinica , 2019 , 47 ( 10 ): 2025 - 2031 . (in Chinese)
Ren Q , He L , Wu J X . Analysis of different anti-interference system models based on discrete time Markov chain [J]. Chinese Journal of Network and Information Security , 2018 , 4 ( 4 ): 30 - 37 . (in Chinese)
Zhang X M , Gu Z Y , Wei S , et al . Markov game modeling of mimic defense and defense strategy determination [J]. Journal on Communications , 2018 , 39 ( 10 ): 143 - 154 . (in Chinese)
Zhang M Y , Wang L Y , Jajodia S , et al . Network diversity: A security metric for evaluating the resilience of networks against zero-day attacks [J]. IEEE Transactions on Information Forensics and Security , 2016 , 11 ( 5 ): 1071 - 1086 .
Miguel G , Bessani A , Neves N . Lazarus: Automatic management of diversity in BFT systems [A]. Proceedings of the 20th International Middleware Conference [C]. New York, USA : ACM , 2019 . 241 - 254 .
Katerina G P , Wang F Y , Wang R , et al . Characterizing intrusion tolerant systems using a state transition model [A]. Proceedings DARPA Information Survivability Conference and Exposition II [C]. Anaheim, USA : IEEE , 2001 . 211 - 221 .
Luo Z Y , Yang X , Sun G L , et al . Study of two kinds of analysis methods of intrusion tolerance system state transition model [J]. Review of Computer Engineering Studies , 2019 , 6 ( 1 ): 23 - 27 .
Miguel G , Bessani A N , Gashi I , et al . OS diversity for intrusion tolerance: Myth or reality? [A]. Proceedings of 2011 IEEE/IFIP 41st International Conference on Dependable Systems & Networks [C]. Hong Kong, China : IEEE , 2011 . 383 - 394 .
Massimiliano A , Connell W , Venkatesan S , et al . Moving target defense quantification [A]. Adversarial and Uncertain Reasoning for Adaptive Cyber Defense [C]. Switzerland AG : Springer , 2019 . 94 - 111 .
Hong J B , Kim D S . Assessing the effectiveness of moving target defenses using Security models [J]. IEEE Transactions on Dependable and Secure Computing , 2016 , 13 ( 2 ): 163 - 177 .
Hong J B , Yusuf E S , Seong K D , et al . Dynamic security metrics for measuring the effectiveness of moving target defense techniques [J]. Computers & Security , 2018 , 79 : 33 - 52 .
Ma D H , Wang L , Lei C , et al . Quantitative security assessment method based on entropy for moving target defense [A]. Proceedings of the 2017 ACM on Asia Conference on Computer and Communications Security [C]. New York, USA : ACM , 2017 . 920 - 922 .
Hooman A , Jin B H , Julian J J , et al . Comprehensive security assessment of combined MTD techniques for the cloud [A]. Proceedings of the 5th ACM Workshop on Moving Target Defense [C]. New York, USA : ACM , 2018 . 11 - 20 .
Brant A C , Corporation T M , Ziring N , et al . Common platform enumeration: Naming specification version 2.3 [R]. US Department of Commerce, NIST Inter-agency Report 7695 , 2011 .
Quinlan J R . Induction of decision trees [J]. Machine Learning , 1986 , 1 ( 1 ): 81 - 106 .