论文标题
一种输入感知的模仿防御理论及其实践
An Input-Aware Mimic Defense Theory and its Practice
论文作者
论文摘要
当前的网络空间安全问题的特征是强烈而复杂的威胁。捍卫者面临许多问题,例如缺乏先验知识,各种威胁和未知漏洞,这些漏洞迫切需要新的基本理论来支持。为了解决这些问题,本文提出了一个通用的网络空间防御和新的模拟防御框架的通用理论模型,即时空异质,输入意识到并动态更新的模仿防御(SIDMD)。我们做出以下贡献:(1)我们首先从输入空间的角度重新定义漏洞,以使各种网络空间安全问题正常化。 (2)我们提出了一种新颖的未知脆弱性发现方法以及一个动态调度策略,即没有先验知识的时间和空间维度。理论分析和实验结果表明,SIDMD在复杂的攻击方案中具有最佳的安全性能,与最新的攻击相比,成功攻击的可能性大大降低了。
The current security problems in cyberspace are characterized by strong and complex threats. Defenders face numerous problems such as lack of prior knowledge, various threats, and unknown vulnerabilities, which urgently need new fundamental theories to support. To address these issues, this article proposes a generic theoretical model for cyberspace defense and a new mimic defense framework, that is, Spatiotemporally heterogeneous, Input aware, and Dynamically updated Mimic Defense (SIDMD). We make the following contributions: (1) We first redefine vulnerabilities from the input space perspective to normalize the diverse cyberspace security problem. (2) We propose a novel unknown vulnerability discovery method and a dynamic scheduling strategy considering temporal and spatial dimensions without prior knowledge. Theoretical analysis and experimental results show that SIDMD has the best security performance in complex attack scenarios, and the probability of successful attacks is greatly reduced compared to the state-of-the-art.