节点文献

一种基于内生安全的攻击反馈动态调度策略

An Attack Feedback Dynamic Scheduling Strategy Based on Endogenous Security

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 陈楠楠; 姜禹; 胡爱群; 郭丞;

【Author】 Chen Nannan;Jiang Yu;Hu Aiqun;Guo Cheng;School of Cyber Science and Engineering, Southeast University;Purple Mountain Laboratories;Key Laboratory of Computer Network Technology of Jiangsu Province (Southeast University);State Key Laboratory of Mobile Communication, Southeast University;School of Education Science, Nanjing Normal University;

【通讯作者】 姜禹;

【机构】 东南大学网络空间安全学院; 紫金山实验室; 江苏省计算机网络技术重点实验室(东南大学); 东南大学移动通信国家重点实验室; 南京师范大学教育科学学院;

【摘要】 为了提高内生安全机制调度策略的高效性和鲁棒性,设计了一种调度时机与调度数量动态调整方法.该方法首先提出一种调度触发器,使用工作时长与异常反馈2种属性共同控制调度进程的切换,并综合考虑系统异构、冗余等因素设计调度工作的整体流程;然后利用历史攻击反馈信息对问题建模,针对不同攻击场景设计更新计算公式,以动态调整调度机制工作时长、执行体数量等属性值;最后设计一个仿真模拟器模拟不同攻击场景,比较各算法运行效果.仿真结果表明,该方法通过自适应调整来协调应对复杂的内外部环境,为DHR结构提供较好的安全性;同时提高执行体利用率,减少冗余资源浪费,以较低的系统开销实现较高的安全增益,性能优于其他单一策略,具有较强的实用性.

【Abstract】 In order to improve the efficiency and robustness of the endogenous security scheduling strategy, a scheduling timing and quantity elastic adjustment method is designed. This method first proposes a scheduling trigger, which uses the two attributes of working time and abnormal feedback to control the switching of scheduling process, and designs the overall flow of scheduling work considering system heterogeneity and redundancy. Then it constructs problem model using historical attack feedback, and designs formulas to dynamically calculate the values for different attack scenarios. Finally, a simulator is designed to simulate different attack scenarios and compare the operation results of each algorithm. Results show that this method can cope with complex internal and external environment through adaptive adjustment, and provide better security for DHR structure. At the same time, it improves the utilization rate of the executor, reduces redundant resource waste, achieves higher security gain with lower system overhead, and outperforms other single strategies, which has strong practicality.

【基金】 江苏省重点研发计划项目(BE2019109);国家自然科学基金项目(61601114,61602113,61801115,61941115,62001106);江苏省自然科学基金项目(BK20160692,BK20200350,BK20200352);江苏省网络与信息安全重点实验室项目(BM2003201);东南大学移动通信国家重点实验室项目(2020B05)
  • 【文献出处】 信息安全研究 ,Journal of Information Security Research , 编辑部邮箱 ,2023年01期
  • 【分类号】TP393.08
  • 【下载频次】65
节点文献中: 

本文链接的文献网络图示:

本文的引文网络