国家数字交换系统工程技术研究中心,河南,郑州,450002
网络出版:2018-11-25,
纸质出版:2018
移动端阅览
陈扬, 扈红超, 程国振. 软件定义的内网动态防御系统设计与实现[J]. 电子学报, 2018,46(11):2604-2611.
CHEN Yang, HU Hong-chao, CHENG Guo-zhen. The Design and Implementation of a Software-Defined Intranet Dynamic Defense System[J]. Acta Electronica Sinica, 2018, 46(11): 2604-2611.
陈扬, 扈红超, 程国振. 软件定义的内网动态防御系统设计与实现[J]. 电子学报, 2018,46(11):2604-2611. DOI: 10.3969/j.issn.0372-2112.2018.11.006.
CHEN Yang, HU Hong-chao, CHENG Guo-zhen. The Design and Implementation of a Software-Defined Intranet Dynamic Defense System[J]. Acta Electronica Sinica, 2018, 46(11): 2604-2611. DOI: 10.3969/j.issn.0372-2112.2018.11.006.
当前,自带设备(BYOD)的兴起对传统基于边界的内网防护观念提出了新的挑战内部不设防导致堡垒易从内部攻破.从扰乱攻击链的角度,本文提出了隔离+动态的防护方法,设计并实现了一种基于软件定义的内网动态防御系统.通过为内网终端分配虚拟IP地址空间,以隐藏各自的真实信息;并且将IP跳变和路径跳变结合起来,实现了更全方面的防护.结果表明,在正常网络应用不受影响的情况下,该系统能大幅降低网络侦察扫描的可用性,阻断网络窃听,提高攻击者实时攻击难度.
The rise of Bring Your Own Device (BYOD) now poses new challenges (the internal undefended causes the citadel to break through from within) to the concept of traditional boundary-based intranet protection. Based on the idea of isolation and dynamic
this paper designs and implements a Software-defined Intranet Dynamic Defense system (SIDD) to harass cyber kill chain. We allocate virtual IP address space for intranet terminals to hide the real IP address
meanwhile
combine the maneuvering of IP and path to achieve more comprehensive protection. Our experiments indicate that this method can significantly reduce the availability of network reconnaissance
block the network eavesdropping
and increase the difficulties of attacker's real-time attack without affecting network applications.
0
浏览量
271
下载量
4
CSCD
关联资源
相关文章
相关作者
相关机构
京公网安备11010802024621