[论文解读] Proactive Defense for Internet-of-Things: Integrating Moving Target Defense with Cyberdeception
本文提出了一种基于软件定义网络(SDN)环境的集成主动防御机制,通过动态网络拓扑切换(即移动目标防御,MTD)与蜜饵节点构成的网络欺骗相结合,实现对物联网(IoT)网络的主动防御。该方法显著延长了系统寿命(MTTSF最高提升60%),提高了攻击复杂度,并保持了较高的服务可用性,其中HS-DPNT策略在多目标优化下表现最优。
Resource constrained Internet-of-Things (IoT) devices are highly likely to be compromised by attackers because strong security protections may not be suitable to be deployed. This requires an alternative approach to protect vulnerable components in IoT networks. In this paper, we propose an integrated defense technique to achieve intrusion prevention by leveraging cyberdeception (i.e., a decoy system) and moving target defense (i.e., network topology shuffling). We verify the effectiveness and efficiency of our proposed technique analytically based on a graphical security model in a software defined networking (SDN)-based IoT network. We develop four strategies (i.e., fixed/random and adaptive/hybrid) to address "when" to perform network topology shuffling and three strategies (i.e., genetic algorithm/decoy attack path-based optimization/random) to address "how" to perform network topology shuffling on a decoy-populated IoT network, and analyze which strategy can best achieve a system goal such as prolonging the system lifetime, maximizing deception effectiveness, maximizing service availability, or minimizing defense cost. Our results demonstrate that a software defined IoT network running our intrusion prevention technique at the optimal parameter setting prolongs system lifetime, increases attack complexity of compromising critical nodes, and maintains superior service availability compared with a counterpart IoT network without running our intrusion prevention technique. Further, when given a single goal or a multi-objective goal (e.g., maximizing the system lifetime and service availability while minimizing the defense cost) as input, the best combination of "how" and "how" strategies is identified for executing our proposed technique under which the specified goal can be best achieved.
研究动机与目标
- 应对资源受限的物联网网络在面对敏捷攻击者时对轻量级、主动安全机制的迫切需求。
- 通过开发主动入侵防护机制,克服传统基于响应的入侵检测系统(IDS)的局限性。
- 将移动目标防御(MTD)与网络欺骗相结合,以增加攻击者的不确定性与复杂度,同时最小化防御开销。
- 在部署蜜饵节点的物联网网络中,优化网络拓扑切换的时机('when')与方式('how'),以实现特定系统目标。
- 构建基于图形化安全模型(GSM)的评估框架,以分析评估所提防御机制的有效性与效率。
提出的方法
- 提出一种新型NTS-MTD(网络拓扑切换-移动目标防御)技术,通过在SDN-based IoT网络中动态重构网络拓扑,误导攻击者。
- 引入四种‘何时切换’策略:固定、随机、自适应与混合,基于系统脆弱性阈值或时间间隔确定最优切换时机。
- 设计三种‘如何切换’策略:遗传算法(GANT)、蜜饵路径优化(DPNT)与随机(RNT),用于确定拓扑重构模式。
- 采用图形化安全模型(GSM)表示攻击图,并计算MTTSF(成功攻击平均时间)、PDR(分组交付比)与欺骗效果等安全指标。
- 在智能医院IoT场景中通过仿真评估性能,涵盖多个目标:系统寿命、欺骗效果、服务可用性与防御成本。
- 应用多目标优化方法,识别在不同系统目标下‘何时’与‘如何’策略的最佳组合,包括成本与鲁棒性之间的权衡。
实验结果
研究问题
- RQ1在部署蜜饵节点的SDN-IoT网络中,哪种‘何时切换’与‘如何切换’策略组合能最大化系统寿命(MTTSF)?
- RQ2通过拓扑切换实现MTD与网络欺骗的集成,相较于基线系统,对欺骗效果与服务可用性有何影响?
- RQ3实际节点与蜜饵节点的数量对攻击路径分布、防御成本与系统鲁棒性有何影响?
- RQ4自适应与混合切换策略相较于固定与随机策略,在防御成本与攻击路径暴露方面表现如何?
- RQ5所提出的基于GSM的评估框架能否有效量化并优化多目标约束下的安全结果?
主要发现
- HS-DPNT策略(混合切换结合蜜饵路径优化拓扑)实现了最高的MTTSF提升(26%),在最大化系统寿命的同时最小化防御成本,表现最优。
- FS-DPNT(固定切换结合DPNT)实现了最高的PDR提升(60%),在最优参数设置下展现出卓越的服务可用性。
- 自适应与混合切换策略(AS/HS)相比固定与随机方案降低了防御成本,尽管其欺骗效果略有下降(通往蜜饵的攻击路径更少)。
- 基于DPNT的切换策略在防御成本方面优于GANT,同时保持了相近的MTTSF与PDR,因此比基于遗传算法的方法更具效率。
- 实际节点数量显著影响攻击路径分布与MTTSF,而蜜饵节点数量虽增加防御成本,对MTTSF影响有限。
- 识别出最优的SSV阈值(系统安全脆弱性水平)与最大延迟参数,可最大化MTTSF,为系统设计者提供可操作的指导。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。