节点文献
基于虚拟专用技术的网络空间防御方法仿真
Simulation of Network Space Defense Method Based on Virtual Private Technology
【摘要】 传统网络防御方法缺乏对未知攻击的转换过程,其攻击检测结果无法更新,导致网络空间防御误报率较高。为此引入虚拟专用技术对网络空间防御方法进行设计与研究。根据实际网络空间防御需求设计整体架构,通过防火墙设置控制网络空间数据。采用防火墙、入侵检测系统与虚拟专用网对网络空间数据进行三层捕获。采用聚类与关联分析算法对数据进行分析,得到未知攻击强规则。依据入侵检测规则库的标准对未知攻击强规则进行转换,并将其添加至入侵检测规则库中并更新,以更新的入侵检测规则库为标准实现网络空间的防御。通过仿真可知,与现有三种方法相比,提出方法的网络空间防御方法极大降低了方法的误报率与漏报率,且未知攻击转换率高、防御精度高,充分说明提出的网络空间防御方法具备更好的防御性能。
【Abstract】 Traditionally, the network defense methods lack the conversion process for unknown attacks, and the attack detection results cannot be updated, resulting in high false alarm rate of network space defense. Therefore, this article introduced a virtual private technology to design and research the method of cyberspace defense. According to the actual network space defense needs, the overall structure was designed. Based on the firewall settings, the network space data was controlled. Moreover, firewall, intrusion detection system and virtual private network were used to capture the network space data. The data was analyzed by the clustering and association analysis algorithm, and then strong rules of unknown attack were obtained. According to the standards of intrusion detection rule base, the strong rules of unknown attacks were transformed and added to the intrusion detection rule base. Then, the intrusion detection rule base was updated. Based on the updated intrusion detection rule base, the network space defense was achieved. Simulation verifies that, compared with the existing methods, the proposed method greatly reduces the false alarm rate and missing alarm rate, and has high conversion rate and high defense accuracy of unknown attack. Therefore, the proposed method has better defense performance.
【Key words】 Virtual private technology; Network space; Defense; Firewall;
- 【文献出处】 计算机仿真 ,Computer Simulation , 编辑部邮箱 ,2020年05期
- 【分类号】TP393.08
- 【被引频次】4
- 【下载频次】63