,Design and implementation of a novel enterprise network defense system bymaneuveringmulti-dimension

来源 :信息与电子工程前沿(英文版) | 被引量 : 0次 | 上传用户:wokaoyouyaozhuce
下载到本地 , 更方便阅读
声明 : 本文档内容版权归属内容提供方 , 如果您对本文有版权争议 , 可与客服联系进行内容授权或下架
论文部分内容阅读
Although the perimeter security model works well enough when all intal hosts are credible, it is becoming increasingly difficult to enforce as companies adopt mobile and cloud technologies, i.e., the rise of bring your own device (BYOD). It is observed that advanced targeted cyber-attacks usually follow a cyber kill chain; for instance, advanced targeted attacks often rely on network scanning techniques to gather information about potential targets. In response to this attack method, we propose a novel approach, i.e., an isolating and dynamic cyber defense, which cuts these potential chains to reduce the cumulative availability of the gathered information. First, we build a zero-trust network environment through network isolation, and then multiple network properties are maneuvered so that the host characteristics and locations needed to identify vulnerabilities cannot be located. Second, we propose a software-defined proactive cyber defense solution (SPD) for enterprise networks and design a general framework to strategically maneuver the IP address, network port, domain name, and path, while limiting the performance impact on the benign network user. Third, we implement our SPD proof-of-concept system over a software-defined network controller (OpenDaylight). Finally, we build an experimental platform to verify the system’s ability to prevent scanning, eavesdropping, and denial-of-service attacks. The results suggest that our system can significantly reduce the availability of network reconnaissance scan information, block network eavesdropping, and sharply increase the cost of cyber-attacks.
其他文献
小麦是世界范围内重要的粮食作物,但是,在其生长发育的各个阶段,病虫害的发生较为严重,极大地影响了小麦产量的稳定和提高。理论和实践都证明,通过选育和推广抗病虫品种是控制病虫
Point set registration has been a topic of significant research interest in the field of mobile intelligent unmanned systems. In this paper, we present a novel
为了维护新闻报道的真实性,河北省张家口日报规定:对失实报道或重大差错,是谁错的以谁的名义在报上更正;所有新闻稿件,从事件发生到见报不得超过一个月,超过期限,又确有必要
20多年来,虽然不断有新组合出现,但是杂交水稻的产量一直徘徊不前,主要原因有二:亲本选育中以农艺性状选择为主,配合力选择进展不大;缺乏有效的优势预测方法。我们借鉴杂交玉米育种中的配子选择,设计了恢复系选育的组合判别法,尝试在农艺性状选择的同时进行配合力选择,同时提高组合早代筛选的效率。试验利用6个恢复系配制的10个单交F_1,然后再与不育系Ⅱ32A和新协黄A配制20个测交组合。对测交组合和测交父本
一、背景通用汽车公司的技术教育规划(以下简称TEP)由通用公司最高工程管理部门于1984年制定设立。通过TEP,这些具有远见卓识的领导人开始推行终身学习这种持久性的文化教育
We use the advanced proximal policy optimization (PPO) reinforcement leaing algorithm to optimize the stochastic control strategy to achieve speed control of th
第一款:名称和目的1、该组织的名称为国际继续工程教育协会,缩写为IACEE,以下简称为“协会”。该协会为一个国际化、非盈利、非政府性组织,在美国法律约束下运行。2、协会目
东北是中国粳稻集中产区.为了满足人们生活水平提高和增强商品稻米市场竞争能力的需要,也为了增加稻米生产的经济收益,该课题以近几年生产上主栽的水稻品种区域试验资料和优
新闻发布会,又称记者招待会,是一个社会组织直接向新闻界发布有关组织信息,解释组织重大事件而举办的活动。政府机关、企事业单位的负责人、特殊公众人物,常利用这种形式主动
We present a double-layered control algorithm to plan the local trajectory for automated trucks equipped with four hub motors. The main layer of the proposed co